cartesi / rollups-contracts

Smart Contracts for Cartesi Rollups
https://cartesi.github.io/rollups-contracts/
Apache License 2.0
17 stars 37 forks source link

ci: tag changesets action by commit SHA #204

Closed guidanoli closed 6 months ago

guidanoli commented 6 months ago

Tags and branches such as v1 can be modified if the repository is compromised. Commit hashes, on the other hand, are unfeasible to craft. Let's adopt this security step whenever secrets (such as API tokens) are exposed to foreign actions. Special thanks to @mpolitzer and @fmoura for the insight. :pray: