Skip to content

Pin token asset push action#55

Merged
murderteeth merged 1 commit into
mainfrom
codex/u1-actions-hardening
May 18, 2026
Merged

Pin token asset push action#55
murderteeth merged 1 commit into
mainfrom
codex/u1-actions-hardening

Conversation

@murderteeth
Copy link
Copy Markdown

Pin the token asset publishing action to an immutable commit.

Notes:

  • Replaces ad-m/github-push-action@master in the workflow path that uses a repository access token.
  • Reduces supply-chain exposure from upstream branch movement.
  • Validated touched workflows with PyYAML and git diff --check.

Please review the following token assets:

📑 Description

  • Token Name: ...
  • Project Website: https://...
  • Explorer URI: https://...

✅ Checks

  • I created a new folder with the token address (all in lowercase for EVM chains, case sensitive for Solana)
  • I added the token's logo as a 32x32 PNG file, named logo-32.png
  • I added the token's logo as a 128x128 PNG file, named logo-128.png
  • I added the token's logo as a SVG file, named logo.svg
  • My SVG logo is a proper SVG and does not contain base64 encoded elements
  • My documentation/website clearly display the token address

Pin the token asset publishing action to an immutable commit.

Notes:
- Replaces `ad-m/github-push-action@master` in the workflow path that uses
  a repository access token.
- Reduces supply-chain exposure from upstream branch movement.
- Validated touched workflows with PyYAML and git diff --check.

Co-Authored-By: OpenAI Codex <noreply@openai.com>
@vercel
Copy link
Copy Markdown

vercel Bot commented May 18, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
token-assets Ready Ready Preview, Comment May 18, 2026 7:01am
token-assets-ui Ready Ready Preview, Comment May 18, 2026 7:01am

Request Review

@murderteeth murderteeth merged commit 6d65220 into main May 18, 2026
4 checks passed
@murderteeth murderteeth deleted the codex/u1-actions-hardening branch May 18, 2026 07:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant