Pin GitHub Actions to commit SHAs - #29
Merged
Merged
Conversation
A tag is a movable label. actions/checkout@v6 runs whatever v6 points at when the job starts, so anyone able to move that tag upstream — through a compromised account, or a maintainer's mistake — runs code in this repository's workflows with its token. A commit SHA cannot be moved. 14 references across the workflows, each resolved from the tag it already used, so nothing changes about which code runs today. The version stays in a trailing comment for readability and because Dependabot reads it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A tag is a movable label.
actions/checkout@v6runs whateverv6points at when thejob starts, so anyone able to move that tag upstream — a compromised account, or a
maintainer's mistake — runs code in this repository's workflows with its token. A commit
SHA cannot be moved.
14 references across the workflows, each resolved from the tag it already used,
so nothing changes about which code runs today. The version stays in a trailing comment
so the file remains readable and Dependabot can keep it current.
Every SHA was checked twice: that the commit exists, and that the tag still resolves to it
(dereferencing annotated tags, where the ref points at a tag object rather than a commit).
🤖 Generated with Claude Code