Commit 46b6ff6
ci: SHA-pin 3rd-party actions
GitHub Actions pinned by tag can be silently replaced if the tag is
moved or the repo is compromised — a tag pin is effectively mutable
auth to our runners. Pin each 3rd-party action to a full commit SHA
with a human-readable tag comment, so tag moves don't propagate
automatically.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>1 parent 841d47e commit 46b6ff6
1 file changed
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
66 | 66 | | |
67 | 67 | | |
68 | 68 | | |
69 | | - | |
| 69 | + | |
0 commit comments