Skip to content

chore: pin codeql-action/upload-sarif to commit SHA#31

Merged
lachen-nv merged 1 commit into
NVIDIA:mainfrom
abegnoche:chore/pin-codeql-action
Mar 24, 2026
Merged

chore: pin codeql-action/upload-sarif to commit SHA#31
lachen-nv merged 1 commit into
NVIDIA:mainfrom
abegnoche:chore/pin-codeql-action

Conversation

@abegnoche

@abegnoche abegnoche commented Mar 24, 2026

Copy link
Copy Markdown
Member

Summary

  • Pin github/codeql-action/upload-sarif to its commit SHA (fdbfb4d2750291e159f0156def62b853c2798ca2) instead of the mutable v4.31.5 tag, following NVIDIA security guidance for action version pinning.

Test plan

  • Verified that the v4.31.5 annotated tag dereferences to commit fdbfb4d2750291e159f0156def62b853c2798ca2 via the GitHub API

Pin github/codeql-action/upload-sarif to its commit SHA
(fdbfb4d2750291e159f0156def62b853c2798ca2) instead of the mutable
v4.31.5 tag, following NVIDIA security guidance.

Made-with: Cursor
@github-actions

github-actions Bot commented Mar 24, 2026

Copy link
Copy Markdown

All contributors have signed the DCO ✍️ ✅
Posted by the DCO Assistant Lite bot.

@abegnoche

Copy link
Copy Markdown
Member Author

I have read the DCO Document and I hereby sign the DCO

github-actions Bot added a commit that referenced this pull request Mar 24, 2026
@abegnoche

Copy link
Copy Markdown
Member Author

recheck

@lachen-nv lachen-nv merged commit ed8101c into NVIDIA:main Mar 24, 2026
2 of 3 checks passed
@github-actions github-actions Bot locked and limited conversation to collaborators Mar 24, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants