Skip to content

[BUILD]: Add commit hashes in verify-poms workflow to pin actions - #838

Merged
MacOS merged 2 commits into
SKaiNET-developers:developfrom
MacOS:verify-poms-workflow/add-commit-hashes
Jul 20, 2026
Merged

MacOS merged 2 commits into
SKaiNET-developers:developfrom
MacOS:verify-poms-workflow/add-commit-hashes

Conversation

@MacOS

@MacOS MacOS commented Jul 20, 2026

Copy link
Copy Markdown
Collaborator

This PR pins all actions in the verify-poms.yml workflow with their commit hash to increase security (#815).

The OpenSSF Score should increase after this PR has been merged.

@MacOS
MacOS requested review from Copilot and michalharakal July 20, 2026 07:03
@MacOS MacOS self-assigned this Jul 20, 2026
@MacOS MacOS added enhancement New feature or request github_actions Pull requests that update GitHub Actions code labels Jul 20, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hard-pins GitHub Actions used in the verify-poms workflow to specific commit SHAs to reduce supply-chain risk and improve the repository’s OpenSSF Score, aligning with issue #815.

Changes:

  • Pin actions/checkout to a specific commit SHA (with an inline version comment).
  • Pin actions/setup-java to a specific commit SHA (with an inline version comment).

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@michalharakal michalharakal left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you @MacOS

@MacOS
MacOS merged commit 49607ac into SKaiNET-developers:develop Jul 20, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants