Skip to content

Improve ci security#212

Merged
DetachHead merged 4 commits into
masterfrom
improve-ci-security2
May 26, 2026
Merged

Improve ci security#212
DetachHead merged 4 commits into
masterfrom
improve-ci-security2

Conversation

@DetachHead
Copy link
Copy Markdown
Owner

@DetachHead DetachHead commented May 25, 2026

addressing some of the security concerns from git/git-scm.com#2132 (comment)

  • pin & verify hash of appimagetool
  • pin actions
  • enable immutable releases
  • include spdx files in the releases

@DetachHead DetachHead mentioned this pull request May 25, 2026
@DetachHead DetachHead force-pushed the improve-ci-security2 branch 3 times, most recently from d758ee2 to 9f91644 Compare May 26, 2026 13:34
@DetachHead DetachHead merged commit 8b42ca5 into master May 26, 2026
14 checks passed
@DetachHead DetachHead deleted the improve-ci-security2 branch May 26, 2026 14:19
DetachHead added a commit that referenced this pull request May 26, 2026
* pin appimagetool in ci and check its hash before using it

* remove outdated comment

* include spdx files in releases

* fix duplicated spdx files

---------

Co-authored-by: detachhead <detachhead@users.noreply.github.com>
(cherry picked from commit 8b42ca5)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant