jbosstools / jbosstools-quarkus

Quarkus tooling for Eclipse
https://tools.jboss.org
Apache License 2.0
17 stars 20 forks source link

Pin 3rd-party actions to SHA1 #205

Closed fbricon closed 1 year ago

fbricon commented 1 year ago

Hi!

Following the GH Action Security Hardening guide we should use the commit SHA instead of the branch or tag for any third-party untrusted action.

This PR was submitted by a script.