Skip to content

CLOUD-410 ktlo: pin GitHub actions to commit SHAs#7

Open
desouradeep wants to merge 2 commits into
masterfrom
ktlo/pin-gh-actions
Open

CLOUD-410 ktlo: pin GitHub actions to commit SHAs#7
desouradeep wants to merge 2 commits into
masterfrom
ktlo/pin-gh-actions

Conversation

@desouradeep
Copy link
Copy Markdown

@desouradeep desouradeep commented May 12, 2026

Action required from the owning team: please review and merge this PR. It was opened as part of an org-wide rollout for CLOUD-410; the Cloud team is not merging on your behalf.

Summary

Pins all external GitHub Actions in this repo from mutable tags (e.g. @v4) to immutable commit SHAs, and ensures dependabot is configured to keep them updated.

Improves supply-chain security per CLOUD-410. Each pinned line keeps the original tag as a trailing comment for readability.

  • Jimdo-owned actions (Jimdo/…) are intentionally not pinned (out of scope per the ticket).
  • Local actions (./...) are untouched.
  • Dependabot is configured (or updated) to track github-actions monthly, on the 1st of each month, at a hour staggered between 09:00–15:00 Europe/Berlin (one fixed hour per repo). A 3-day cooldown filters out brand-new releases.

Test plan

  • CI passes
  • No unintended changes outside .github/

@desouradeep desouradeep added the cloud-410 CLOUD-410: pin GitHub actions to commit SHAs label May 12, 2026
@desouradeep desouradeep changed the title ktlo: pin GitHub actions to commit SHAs CLOUD-410 ktlo: pin GitHub actions to commit SHAs May 12, 2026
@desouradeep desouradeep marked this pull request as ready for review May 13, 2026 11:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cloud-410 CLOUD-410: pin GitHub actions to commit SHAs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant