Skip to content

chore: sha-pin actions#40

Open
JohnTitor wants to merge 1 commit intorust-netlink:mainfrom
JohnTitor:gha
Open

chore: sha-pin actions#40
JohnTitor wants to merge 1 commit intorust-netlink:mainfrom
JohnTitor:gha

Conversation

@JohnTitor
Copy link
Copy Markdown
Member

To prevent supply-chain attacks. Also update action versions.

@gemini-code-assist
Copy link
Copy Markdown

Note

Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported.

@cathay4t
Copy link
Copy Markdown
Member

Any more detail on this supply-chain attacks?

This is for CI system, how could this attack impact us?

@JohnTitor
Copy link
Copy Markdown
Member Author

@cathay4t
Copy link
Copy Markdown
Member

I have changed the github setting to limit Workflow permissions to READ only. That seems better fix comparing to Audit the source code of the action and Pin actions to a tag only if you trust the creator

@cathay4t
Copy link
Copy Markdown
Member

cathay4t commented Apr 1, 2026

With Workflow permissions already changed to READ only, do we still this PR?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants