-
Notifications
You must be signed in to change notification settings - Fork 1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Pin GitHub Actions to Git commit hash #27
Comments
achrinza
added a commit
to loopbackio/loopback-next
that referenced
this issue
Aug 28, 2022
see: loopbackio/security#27 Signed-off-by: Rifa Achrinza <[email protected]>
3 tasks
achrinza
added a commit
to loopbackio/loopback-next
that referenced
this issue
Aug 28, 2022
see: loopbackio/security#27 Signed-off-by: Rifa Achrinza <[email protected]>
achrinza
added a commit
to loopbackio/loopback-next
that referenced
this issue
Aug 28, 2022
see: loopbackio/security#27 Signed-off-by: Rifa Achrinza <[email protected]>
achrinza
added a commit
to loopbackio/loopback-next
that referenced
this issue
Aug 28, 2022
see: loopbackio/security#27 Signed-off-by: Rifa Achrinza <[email protected]>
achrinza
added a commit
to loopbackio/loopback-next
that referenced
this issue
Aug 28, 2022
see: loopbackio/security#27 Signed-off-by: Rifa Achrinza <[email protected]>
achrinza
added a commit
to loopbackio/loopback-connector
that referenced
this issue
Aug 28, 2022
see: loopbackio/security#27 Signed-off-by: Rifa Achrinza <[email protected]>
3 tasks
achrinza
added a commit
to loopbackio/loopback-connector
that referenced
this issue
Aug 28, 2022
see: loopbackio/security#27 Signed-off-by: Rifa Achrinza <[email protected]>
achrinza
added a commit
to loopbackio/loopback.io
that referenced
this issue
Aug 28, 2022
see: loopbackio/security#27 Signed-off-by: Rifa Achrinza <[email protected]>
achrinza
added a commit
to loopbackio/loopback-connector
that referenced
this issue
Aug 28, 2022
see: loopbackio/security#27 Signed-off-by: Rifa Achrinza <[email protected]>
achrinza
added a commit
to loopbackio/loopback.io
that referenced
this issue
Sep 3, 2022
see: loopbackio/security#27 Signed-off-by: Rifa Achrinza <[email protected]>
achrinza
added a commit
to loopbackio/loopback-next
that referenced
this issue
Sep 8, 2022
see: loopbackio/security#27 Signed-off-by: Rifa Achrinza <[email protected]>
achrinza
added a commit
to loopbackio/loopback-next
that referenced
this issue
Sep 8, 2022
see: loopbackio/security#27 Signed-off-by: Rifa Achrinza <[email protected]>
achrinza
added a commit
to loopbackio/loopback-connector-mongodb
that referenced
this issue
Oct 24, 2022
- Prepare Renovate config for v6.x branch - Tidy pipeline code - Drop uneeded test matrix (semver-major release) - Pin GitHub Actions action to Git commit hash see: loopbackio/security#27 see: #720 Signed-off-by: Rifa Achrinza <[email protected]>
achrinza
added a commit
to loopbackio/cicd
that referenced
this issue
Aug 30, 2023
see: loopbackio/security#27 Signed-off-by: Rifa Achrinza <[email protected]>
achrinza
added a commit
to loopbackio/cicd
that referenced
this issue
Aug 30, 2023
see: loopbackio/security#27 Signed-off-by: Rifa Achrinza <[email protected]>
achrinza
added a commit
to loopbackio/strong-soap
that referenced
this issue
Oct 26, 2023
see: loopbackio/security#27 Signed-off-by: Rifa Achrinza <[email protected]>
achrinza
added a commit
to loopbackio/strong-soap
that referenced
this issue
Oct 26, 2023
see: loopbackio/security#27 Signed-off-by: Rifa Achrinza <[email protected]>
achrinza
added a commit
to loopbackio/strong-soap
that referenced
this issue
Oct 26, 2023
see: loopbackio/security#27 Signed-off-by: Rifa Achrinza <[email protected]>
achrinza
added a commit
to loopbackio/strong-error-handler
that referenced
this issue
Nov 9, 2023
see: loopbackio/cicd#91 see: loopbackio/cicd#90 see: loopbackio/cicd#89 see: loopbackio/cicd#83 see: loopbackio/security#27 see: loopbackio/security#26 see: loopbackio/security#23 see: loopbackio/security#16 Signed-off-by: Rifa Achrinza <[email protected]>
achrinza
added a commit
to loopbackio/strong-error-handler
that referenced
this issue
Nov 9, 2023
see: loopbackio/cicd#91 see: loopbackio/cicd#90 see: loopbackio/cicd#89 see: loopbackio/cicd#83 see: loopbackio/security#27 see: loopbackio/security#26 see: loopbackio/security#23 see: loopbackio/security#16 Signed-off-by: Rifa Achrinza <[email protected]>
achrinza
added a commit
to loopbackio/strong-error-handler
that referenced
this issue
Nov 9, 2023
see: loopbackio/cicd#91 see: loopbackio/cicd#90 see: loopbackio/cicd#89 see: loopbackio/cicd#83 see: loopbackio/security#27 see: loopbackio/security#26 see: loopbackio/security#23 see: loopbackio/security#16 Signed-off-by: Rifa Achrinza <[email protected]>
achrinza
added a commit
to loopbackio/strong-error-handler
that referenced
this issue
Nov 9, 2023
see: loopbackio/cicd#91 see: loopbackio/cicd#90 see: loopbackio/cicd#89 see: loopbackio/cicd#83 see: loopbackio/security#27 see: loopbackio/security#26 see: loopbackio/security#23 see: loopbackio/security#16 Signed-off-by: Rifa Achrinza <[email protected]>
achrinza
added a commit
to loopbackio/strong-error-handler
that referenced
this issue
Nov 9, 2023
see: loopbackio/cicd#91 see: loopbackio/cicd#90 see: loopbackio/cicd#89 see: loopbackio/cicd#83 see: loopbackio/security#27 see: loopbackio/security#26 see: loopbackio/security#23 see: loopbackio/security#16 Signed-off-by: Rifa Achrinza <[email protected]>
achrinza
added a commit
to loopbackio/strong-error-handler
that referenced
this issue
Nov 9, 2023
see: https://github.com/loopbackio/strong-error-handler/security/code-scanning/7 see: https://github.com/loopbackio/strong-error-handler/security/code-scanning/6 see: https://github.com/loopbackio/strong-error-handler/security/code-scanning/5 see: loopbackio/security#27 Signed-off-by: Rifa Achrinza <[email protected]>
dhmlau
pushed a commit
to loopbackio/strong-error-handler
that referenced
this issue
Dec 7, 2023
see: https://github.com/loopbackio/strong-error-handler/security/code-scanning/7 see: https://github.com/loopbackio/strong-error-handler/security/code-scanning/6 see: https://github.com/loopbackio/strong-error-handler/security/code-scanning/5 see: loopbackio/security#27 Signed-off-by: Rifa Achrinza <[email protected]>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Currently, we're inconsistently referencing third-party GitHub Actions by Git tags, Git branches and the Git commit hash.
Git tags and Git branches can be re-pointed to a different Git commit hash without our explicit knowledge. Hence, this poses a security risk as a malicious GitHub Action that we depend on can go under the radar without our knowledge.
We should standardise on referencing by Git commit hash.
Renovate currently handles keeping the GitHub Actions up-to-date. It supports updating Git commit hash while following the Git tags:
The syntax would be either of the following:
Loosely-related to #25 (Part of OpenSSF Scorecard check).
GitHub repositories
The text was updated successfully, but these errors were encountered: