Skip to content

chore: [SEC-7924] pin third-party GitHub Actions to commit SHAs#668

Open
pkaeding wants to merge 1 commit intomainfrom
security/SEC-7924/pin-github-actions
Open

chore: [SEC-7924] pin third-party GitHub Actions to commit SHAs#668
pkaeding wants to merge 1 commit intomainfrom
security/SEC-7924/pin-github-actions

Conversation

@pkaeding
Copy link
Contributor

@pkaeding pkaeding commented Mar 24, 2026

Summary

Pin all third-party GitHub Actions to full-length commit SHAs to prevent supply chain attacks.

Addresses findings from the third-party-action-not-pinned-to-commit-sha Semgrep rule.

Test plan

  • Verify CI passes with pinned action SHAs

Note

Low Risk
Low risk: this only changes GitHub Actions references to fixed commit SHAs; failures would be limited to CI/workflow execution if a pinned SHA is incorrect or later removed.

Overview
Hardens CI by pinning several third-party GitHub Actions to full commit SHAs instead of floating version tags.

This updates the publish composite action (docker/setup-qemu-action, docker/setup-buildx-action) and workflows (rtCamp/action-slack-notify, pre-commit/action, google-github-actions/release-please-action) without changing the workflow logic.

Written by Cursor Bugbot for commit 5c4e967. This will update automatically on new commits. Configure here.


Related Jira issue: SEC-7924: Unpinned GitHub Actions remediation

Pin all third-party GitHub Actions to full-length commit SHAs to prevent
supply chain attacks. Addresses findings from the
third-party-action-not-pinned-to-commit-sha Semgrep rule.
@launchdarkly-upra launchdarkly-upra bot changed the title chore: pin third-party GitHub Actions to commit SHAs chore: [SEC-7924] pin third-party GitHub Actions to commit SHAs Mar 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant