trivy-action icon indicating copy to clipboard operation
trivy-action copied to clipboard

Should we pin to `master` when Github advises pinning to full git SHA?

Open bixu opened this issue 1 year ago • 1 comments

https://github.com/aquasecurity/trivy-action/blob/cb606dfdb0d2b3698ace62192088ef4f5360b24f/README.md?plain=1#L70

See https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-third-party-actions

bixu avatar Aug 05 '22 13:08 bixu

Fair enough - you can pin to a full SHA as you mentioned. The documentation is simply a suggestion and not a requirement.

simar7 avatar Aug 10 '22 18:08 simar7