Skip to content

chore: pin GitHub Actions to SHA#8666

Open
cafe6a6e wants to merge 1 commit intotensorflow:masterfrom
cafe6a6e:sha-pinning-actions
Open

chore: pin GitHub Actions to SHA#8666
cafe6a6e wants to merge 1 commit intotensorflow:masterfrom
cafe6a6e:sha-pinning-actions

Conversation

@cafe6a6e
Copy link
Copy Markdown

@cafe6a6e cafe6a6e commented Apr 2, 2026

This PR pins the GitHub Actions to a specific SHA to prevent supply chain attacks.

Pinned actions

action name version SHA
actions/checkout v4.3.1 34e114876b0b11c390a56381ad16ebd13914f8d5
bazel-contrib/setup-bazel 0.14.0 5483a91b6e3ffac6092848f1dd7eafcfad203d80
actions/setup-node v4.4.0 49933ea5288caeca8642d1e84afbd3f7d6820020
actions/stale v7.0.0 6f05e4244c9a0b2ed3401882b05d701dd0a7289b
actions/checkout v2.7.0 ee0669bd1cc54295c223e0bb666b733df41de1c5
FirebaseExtended/action-hosting-deploy v0.9.0 0cbcac4740c2bfb00d632f0b863b57713124eb5a

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant