redhat-developer / app-services-sdk-js

RHOAS SDK for JavaScript and Typescript
https://redhat-developer.github.io/app-services-sdk-js
Apache License 2.0
3 stars 16 forks source link

Pin 3rd-party actions to SHA1 #644

Closed fbricon closed 1 year ago

fbricon commented 1 year ago

Hi!

Following the GH Action Security Hardening guide we should use the commit SHA instead of the branch or tag for any third-party untrusted action.

This PR was submitted by a script.