Skip to content

ci: pin GitHub Actions to full commit SHAs#22215

Open
XananasX7 wants to merge 2 commits into
php:masterfrom
XananasX7:fix/pin-actions-to-sha
Open

ci: pin GitHub Actions to full commit SHAs#22215
XananasX7 wants to merge 2 commits into
php:masterfrom
XananasX7:fix/pin-actions-to-sha

Conversation

@XananasX7
Copy link
Copy Markdown

This PR pins GitHub Actions from mutable version tags (e.g. @v4) to full commit SHAs, preventing silent supply chain attacks from compromised action repositories.

Recommended by GitHub's security hardening guide and OpenSSF Scorecard.

XananasX7 added 2 commits June 3, 2026 02:55
Signed-off-by: El Mehdi Abenhazou <mehdiananas007@gmail.com>
@TimWolla TimWolla requested a review from edorian June 3, 2026 06:42
@edorian
Copy link
Copy Markdown
Member

edorian commented Jun 3, 2026

Hi XananasX,

I can see the reasoning for pinning 3rd party actions, if we have a process to update them in place.

The PR/diff is empty for me, did something go wrong?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants