Skip to content

[ACIX-1926] chore(ci): pin GitHub Actions to commit SHAs - #298

Open
Ishirui wants to merge 1 commit into
mainfrom
pin-github-actions-to-sha
Open

[ACIX-1926] chore(ci): pin GitHub Actions to commit SHAs#298
Ishirui wants to merge 1 commit into
mainfrom
pin-github-actions-to-sha

Conversation

@Ishirui

@Ishirui Ishirui commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Mechanical rewrite of every uses: reference to a full-length commit SHA, produced by pinact. An unpinned reference resolves to a mutable ref, so a compromise of the upstream action becomes code execution in this repository's CI.

The trailing # vX.Y.Z comment is what lets Renovate and Dependabot keep these bumped, so please keep it.

One thing to check: references that tracked @main or @master were resolved to the latest stable tag. If any of them floated deliberately and that behaviour was load-bearing here, say so on the PR and we will revert that line.

@Ishirui
Ishirui requested a review from a team as a code owner August 4, 2026 16:17
@datadog-datadog-prod-us1

datadog-datadog-prod-us1 Bot commented Aug 4, 2026

Copy link
Copy Markdown

🎯 Code Coverage (details)
Patch Coverage: 100.00%
Overall Coverage: 70.22% (+0.03%)

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 217e5dd | Docs | Datadog PR Page | Give us feedback!

@Ishirui Ishirui changed the title chore(ci): pin GitHub Actions to commit SHAs [ACIX-1926] chore(ci): pin GitHub Actions to commit SHAs Aug 5, 2026
Mechanical rewrite of every `uses:` reference to a full-length commit SHA, produced by [pinact](https://github.com/suzuki-shunsuke/pinact). An unpinned reference resolves to a mutable ref, so a compromise of the upstream action becomes code execution in this repository's CI.

The trailing `# vX.Y.Z` comment is what lets Renovate and Dependabot keep these bumped, so please keep it.

**One thing to check:** references that tracked `@main` or `@master` were resolved to the latest stable tag. If any of them floated deliberately and that behaviour was load-bearing here, say so on the PR and we will revert that line.
@Ishirui
Ishirui force-pushed the pin-github-actions-to-sha branch from ec5f099 to 217e5dd Compare August 5, 2026 14:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant