Skip to content

Conversation

@TohaUA
Copy link

@TohaUA TohaUA commented Nov 28, 2025

Automated pinning of GitHub Actions to their commit SHAs.

This improves security by preventing supply chain attacks through compromised action tags.
Each action is pinned to its current commit SHA with a comment showing the original version.

Related Ticket

https://getpantheon.atlassian.net/browse/DELENG-235

Need Help?

If you have questions or need help, ask in Slack #ask-delivery-engineering

@TohaUA TohaUA requested a review from a team as a code owner November 28, 2025 08:25
@github-actions
Copy link

👋 @TohaUA
Thanks for opening your first pull request! @pantheon-systems/docs-admins is excited to review this!

If you like this project, please ⭐star⭐ our repo.

@pantheon-decoupled
Copy link

⚡ Deployed with Pantheon Decoupled

This build was successfully deployed with Pantheon. You can track the build logs here.

👀 Preview: https://pr-9789-documentation.appa.pantheon.site
🛠️ Manage in Pantheon: https://dashboard.pantheon.io/site/2b30153f-e8b1-4427-b076-6109e704ba5d/overview

@rachelwhitton rachelwhitton added Type: Fix Content Issue or PR to resolve incorrect information in the docs Topic: Automation labels Dec 4, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Topic: Automation Type: Fix Content Issue or PR to resolve incorrect information in the docs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants