Skip to content

Pin GitHub Actions to specific commit SHAs for security#3294

Merged
Herklos merged 1 commit intodevfrom
claude/fix-actions-fork-security-92Sen
Mar 17, 2026
Merged

Pin GitHub Actions to specific commit SHAs for security#3294
Herklos merged 1 commit intodevfrom
claude/fix-actions-fork-security-92Sen

Conversation

@Herklos
Copy link
Copy Markdown
Contributor

@Herklos Herklos commented Mar 5, 2026

No description provided.

@Herklos Herklos requested a review from GuillaumeDSM as a code owner March 5, 2026 08:02
@Herklos Herklos enabled auto-merge (rebase) March 5, 2026 08:15
@Herklos Herklos disabled auto-merge March 17, 2026 08:41
@Herklos Herklos force-pushed the claude/fix-actions-fork-security-92Sen branch from 4df76ea to 5cdab7e Compare March 17, 2026 08:42
@Herklos Herklos enabled auto-merge (rebase) March 17, 2026 08:42
- Add top-level `permissions: read-all` to restrict GITHUB_TOKEN to read-only by default
- Add per-job permissions for docker (packages: write) and release (contents: write) jobs
- Pin all third-party actions to full commit SHAs instead of mutable tags
- Replace dangerous `docker/build-push-action@master` with stable v6 pinned to SHA
- Pin internal reusable workflow to commit SHA

https://claude.ai/code/session_01LWawuSwikT1qRjtryfbtRF
@Herklos Herklos force-pushed the claude/fix-actions-fork-security-92Sen branch from 5cdab7e to 8eb4a7c Compare March 17, 2026 08:42
@Herklos Herklos merged commit e983dd4 into dev Mar 17, 2026
18 checks passed
@Herklos Herklos deleted the claude/fix-actions-fork-security-92Sen branch March 17, 2026 08:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants