Skip to content

[DEV-72] chore: pin GitHub Actions to commit SHAs#1040

Open
austinpray-mixpanel wants to merge 1 commit intomasterfrom
pin-actions-to-sha
Open

[DEV-72] chore: pin GitHub Actions to commit SHAs#1040
austinpray-mixpanel wants to merge 1 commit intomasterfrom
pin-actions-to-sha

Conversation

@austinpray-mixpanel
Copy link
Member

@austinpray-mixpanel austinpray-mixpanel commented Mar 24, 2026

Summary

Pin all GitHub Actions workflow steps to immutable full commit SHAs instead of mutable tags or branches.

Why

Mutable tags can be moved after the fact, making it possible for a supply-chain attack to inject malicious code into CI. Pinning to a commit SHA ensures the exact version of an action is used, and the original tag is preserved as an inline comment for readability.

Verification

Review the diff — all uses: lines with third-party actions should now reference a 40-character commit SHA with the original tag as an inline comment.

🤖 Generated with Claude Code

Linear: https://linear.app/mixpanel/issue/DEV-72/pin-all-github-actions-to-commit-shas

@austinpray-mixpanel austinpray-mixpanel changed the title chore: pin GitHub Actions to commit SHAs [DEV-72] chore: pin GitHub Actions to commit SHAs Mar 24, 2026
@linear
Copy link

linear bot commented Mar 24, 2026

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant