gitpod
gitpod copied to clipboard
chore: pin GitHub Actions to SHA (PDE-215)
Pin all external GitHub Actions to specific commit SHAs for supply chain security.
Changes
27 unique actions pinned (~100 references across 22 workflow files):
actions/cache@v3actions/checkout@master,@v2,@v4actions/github-script@v6,@v7actions/setup-go@v2actions/setup-java@v4actions/stale@v9actions/upload-artifact@v4authzed/[email protected]BetaHuhn/repo-file-sync-action@v1bufbuild/buf-breaking-action@v1bufbuild/buf-lint-action@v1bufbuild/buf-setup-action@v1configcat/scan-repository@v2docker/login-action@v3FedericoCarboni/setup-ffmpeg@v1filiptronicek/get-last-job-status@maingoogle-github-actions/auth@v1imjasonh/[email protected]KeisukeYamashita/create-comment@v1peter-evans/create-pull-request@v6rtCamp/action-slack-notify@v2slackapi/[email protected]test-summary/action@v2transferwise/sanitize-branch-name@v1
Exceptions
gitpod-io/[email protected]: internal Gitpod action, not pinned to SHA
Related
:warning: Hey reviewer! BE CAREFUL :warning:
Review the code before opening in your Gitpod. .gitpod.yml was changed and it might be harmful.