Skip to content

Conversation

@corneliusludmann
Copy link
Contributor

Pin all external GitHub Actions to specific commit SHAs for supply chain security.

Changes

  • actions/cache@v4 → pinned to SHA
  • actions/checkout@v5 → pinned to SHA
  • actions/setup-node@v5 → pinned to SHA
  • PlasmoHQ/bpp@v3 → pinned to SHA
  • pnpm/action-setup@v4 → pinned to SHA

Related

Pin all external GitHub Actions to specific commit SHAs to prevent
supply chain attacks via malicious tag updates.

Actions pinned:
- actions/cache@v4
- actions/checkout@v5
- actions/setup-node@v5
- PlasmoHQ/bpp@v3
- pnpm/action-setup@v4

Part of PDE-138
Closes PDE-216

Co-authored-by: Ona <[email protected]>
@corneliusludmann corneliusludmann marked this pull request as ready for review December 10, 2025 11:26
@corneliusludmann corneliusludmann merged commit 7ea69c2 into main Dec 11, 2025
1 check passed
@corneliusludmann corneliusludmann deleted the cl/pde-216-pin-gha branch December 11, 2025 14:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants