Skip to content

Conversation

@kinyoklion
Copy link
Member

No description provided.

@semgrep-code-launchdarkly
Copy link

Semgrep found 11 third-party-action-not-pinned-to-commit-sha findings:

An action sourced from a third-party repository on GitHub is not pinned to a full length commit SHA. Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps mitigate the risk of a bad actor adding a backdoor to the action's repository, as they would need to generate a SHA-1 collision for a valid Git object payload.

@kinyoklion kinyoklion closed this Oct 18, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants