Skip to content

security: pin GitHub Actions to commit SHAs#200

Merged
mattrobenolt merged 1 commit into
mainfrom
security/pin-gha-actions
May 12, 2026
Merged

security: pin GitHub Actions to commit SHAs#200
mattrobenolt merged 1 commit into
mainfrom
security/pin-gha-actions

Conversation

@mattrobenolt
Copy link
Copy Markdown
Member

@mattrobenolt mattrobenolt commented May 12, 2026

Pins all GitHub Actions workflow steps to immutable commit SHAs instead of mutable tags, following supply chain security best practices.

Changes:

  • All uses: action@tag refs updated to latest versions and pinned to SHAs
  • Added renovate.json5 extending planetscale/renovate-config so felix keeps these pinned and up-to-date going forward

@mattrobenolt mattrobenolt enabled auto-merge (squash) May 12, 2026 18:15
@mattrobenolt mattrobenolt merged commit ab11cb6 into main May 12, 2026
5 checks passed
@mattrobenolt mattrobenolt deleted the security/pin-gha-actions branch May 12, 2026 18:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants