Skip to content

fix: pin third-party actions to SHA to prevent supply chain attacks#1

Merged
tokict merged 1 commit into
masterfrom
fix/pin-actions-to-sha
Mar 24, 2026
Merged

fix: pin third-party actions to SHA to prevent supply chain attacks#1
tokict merged 1 commit into
masterfrom
fix/pin-actions-to-sha

Conversation

@tokict
Copy link
Copy Markdown

@tokict tokict commented Mar 24, 2026

Pins haskell-actions/setup and ikalnytskyi/action-setup-postgres to immutable commit SHAs. Mutable semver tags are vulnerable to supply chain attacks via tag hijacking (ref: GHSA-69fq-xp46-6x23).

@tokict tokict merged commit b637b41 into master Mar 24, 2026
0 of 17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant