Skip to content

[DEV-72] chore: pin GitHub Actions to commit SHAs#213

Merged
tylerjroach merged 1 commit intomainfrom
pin-actions-to-sha
Mar 31, 2026
Merged

[DEV-72] chore: pin GitHub Actions to commit SHAs#213
tylerjroach merged 1 commit intomainfrom
pin-actions-to-sha

Conversation

@austinpray-mixpanel
Copy link
Copy Markdown
Member

@austinpray-mixpanel austinpray-mixpanel commented Mar 24, 2026

Summary

Pin all GitHub Actions workflow steps to immutable full commit SHAs instead of mutable tags or branches.

Why

Mutable tags can be moved after the fact, making it possible for a supply-chain attack to inject malicious code into CI. Pinning to a commit SHA ensures the exact version of an action is used, and the original tag is preserved as an inline comment for readability.

Verification

Review the diff — all uses: lines with third-party actions should now reference a 40-character commit SHA with the original tag as an inline comment.

🤖 Generated with Claude Code

Linear: https://linear.app/mixpanel/issue/DEV-72/pin-all-github-actions-to-commit-shas

@austinpray-mixpanel austinpray-mixpanel requested review from a team, ebracho and krishna16v and removed request for a team March 24, 2026 14:06
@austinpray-mixpanel austinpray-mixpanel changed the title chore: pin GitHub Actions to commit SHAs [DEV-72] chore: pin GitHub Actions to commit SHAs Mar 24, 2026
@linear
Copy link
Copy Markdown

linear Bot commented Mar 24, 2026

@austinpray-mixpanel austinpray-mixpanel requested a review from a team March 24, 2026 21:23
@gmasnica gmasnica self-requested a review March 24, 2026 23:13
@gmasnica gmasnica removed the request for review from krishna16v March 24, 2026 23:16
@tylerjroach tylerjroach merged commit 73a1e12 into main Mar 31, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants