]> git.ipfire.org Git - thirdparty/xz.git/commit
CI: Bump and ref actions by commit SHA in ci.yml
authorGabriela Gutierrez <gabigutierrez@google.com>
Tue, 26 Sep 2023 14:35:08 +0000 (14:35 +0000)
committerJia Tan <jiat0218@gmail.com>
Fri, 13 Oct 2023 12:03:13 +0000 (20:03 +0800)
commitf28cc9bd481ce493da11f98c18526d324211599a
tree863b8ee8e077039f4c6752b81e8cafd2c735923f
parentf74f1740067b75042497edbfa6ea457ff75484b9
CI: Bump and ref actions by commit SHA in ci.yml

Referencing actions by commit SHA in GitHub workflows guarantees you are using an immutable version. Actions referenced by tags and branches are more vulnerable to attacks, such as the tag being moved to a malicious commit or a malicious commit being pushed to the branch.

It's important to make sure the SHA's are from the original repositories and not forks.

For reference:

https://github.com/actions/checkout/releases/tag/v4.1.0
https://github.com/actions/checkout/commit/8ade135a41bc03ea155e62e844d188df1ea18608

https://github.com/actions/upload-artifact/releases/tag/v3.1.3
https://github.com/actions/upload-artifact/commit/a8a3f3ad30e3422c9c7b888a15615d19a852ae32

Signed-off-by: Gabriela Gutierrez <gabigutierrez@google.com>
.github/workflows/ci.yml