ci: pin actions to commit SHAs to prevent RCE
Some checks failed
Check / check (pull_request) Failing after 5m27s
Some checks failed
Check / check (pull_request) Failing after 5m27s
Pin actions/checkout and actions/setup-go to their full commit SHAs instead of mutable tags, per review feedback. - actions/checkout@v4 → 34e114876b0b11c390a56381ad16ebd13914f8d5 - actions/setup-go@v5 → 40f1582b2485089dde7abd97c1529aa768e1baff
This commit is contained in:
parent
f65e3887b2
commit
5d87d386c3
@ -10,9 +10,9 @@ jobs:
|
||||
check:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
|
||||
|
||||
- uses: actions/setup-go@v5
|
||||
- uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5
|
||||
with:
|
||||
go-version-file: go.mod
|
||||
|
||||
|
||||
Loading…
Reference in New Issue
Block a user