Skip to content

ci: pin actions to full commit SHAs#1800

Open
eepifanova wants to merge 2 commits into
mainfrom
pin-actions
Open

ci: pin actions to full commit SHAs#1800
eepifanova wants to merge 2 commits into
mainfrom
pin-actions

Conversation

@eepifanova

Copy link
Copy Markdown
Contributor

Pin action refs from mutable tags to full commit SHAs to prevent supply-chain attacks.

  • actions/upload-artifact: v6.0.0 -> b7c566a7...
  • actions/download-artifact: v7 -> 37930b1c...
  • azure/login: v2 -> a457da9e...
  • actions/labeler: v6 -> 634933ed...

Actions are pinned to the same versions as it was before. No behaviour changes

Pin action refs from mutable tags to full commit SHAs to prevent
supply-chain attacks.

- actions/upload-artifact: v6.0.0 -> b7c566a7...
- actions/download-artifact: v7 -> 37930b1c...
- azure/login: v2 -> a457da9e...
- actions/labeler: v6 -> 634933ed...

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@eepifanova eepifanova requested a review from a team as a code owner March 26, 2026 11:35
@github-actions github-actions Bot added the tooling Back end, repository, Hugo, and all things not related to content label Mar 26, 2026
@github-actions

Copy link
Copy Markdown

Deploy Preview will be available once build job completes!

Name Link
😎 Deploy Preview https://frontdoor-test-docs.nginx.com/previews/docs/1800/

@github-actions

Copy link
Copy Markdown

This PR is stale because it has been open 90 days with no activity. Remove the stale label or add a comment to keep it open. If you do not take action, this will be closed in 10 days.

@github-actions github-actions Bot added the stale label Jun 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

stale tooling Back end, repository, Hugo, and all things not related to content

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants