Skip to content

chore: fix version designation on pinned action#359

Merged
keelerm84 merged 2 commits intov7from
security/SEC-7924/pin-github-actions
Apr 1, 2026
Merged

chore: fix version designation on pinned action#359
keelerm84 merged 2 commits intov7from
security/SEC-7924/pin-github-actions

Conversation

@pkaeding
Copy link
Copy Markdown
Contributor

Summary

Pin all third-party GitHub Actions to full-length commit SHAs to prevent supply chain attacks.

Addresses findings from the third-party-action-not-pinned-to-commit-sha Semgrep rule.

Test plan

  • Verify CI passes with pinned action SHAs

Pin all third-party GitHub Actions to full-length commit SHAs to prevent
supply chain attacks. Addresses findings from the
third-party-action-not-pinned-to-commit-sha Semgrep rule.
@pkaeding pkaeding requested a review from a team as a code owner March 31, 2026 22:45
Copy link
Copy Markdown

@cursor cursor bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.

Co-authored-by: Matthew M. Keeler <mkeeler@launchdarkly.com>
@pkaeding pkaeding closed this Apr 1, 2026
@keelerm84 keelerm84 reopened this Apr 1, 2026
@keelerm84 keelerm84 changed the title chore: pin third-party GitHub Actions to commit SHAs chore: fix version designation on pinned action Apr 1, 2026
@keelerm84 keelerm84 merged commit 25f75be into v7 Apr 1, 2026
59 checks passed
@keelerm84 keelerm84 deleted the security/SEC-7924/pin-github-actions branch April 1, 2026 17:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants