Skip to content

chore: pin third-party GitHub Actions to commit SHAs#392

Merged
cyaiox merged 3 commits into
mainfrom
security/pin-github-actions-sha
May 18, 2026
Merged

chore: pin third-party GitHub Actions to commit SHAs#392
cyaiox merged 3 commits into
mainfrom
security/pin-github-actions-sha

Conversation

@decentraland-bot

Copy link
Copy Markdown
Contributor

Summary

Pin mutable branch references (@master) on third-party GitHub Actions to immutable commit SHAs, preventing supply chain attacks if a third-party maintainer account is compromised.

Actions pinned:

  • menduz/oddish-action@master@b08e3123

The SHA comment preserves the original human-readable reference.

Requested by Ignacio Mazzara via Slack

@decentraland-bot decentraland-bot changed the title ci: pin third-party GitHub Actions to commit SHAs chore: pin third-party GitHub Actions to commit SHAs May 18, 2026
@cyaiox cyaiox merged commit 131dd8b into main May 18, 2026
1 check passed
@cyaiox cyaiox deleted the security/pin-github-actions-sha branch May 18, 2026 18:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants