From 608594f7403187780cabff4bce9c0910b619b6b2 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Martin=20Ad=C3=A1mek?= Date: Thu, 20 Aug 2026 13:08:20 +0200 Subject: [PATCH] ci: pin third-party actions to commit SHAs Floating tags can move to broken or malicious commits, as happened with EndBug/add-and-commit v11 (see apify/crawlee#4051). Pin all third-party actions to full commit SHAs with the resolved version tag in a trailing comment. Own-org (apify/*) references stay on floating refs. --- .github/workflows/check_dist.yaml | 2 +- .github/workflows/pr_toolkit.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/check_dist.yaml b/.github/workflows/check_dist.yaml index c74b796..9598a7b 100644 --- a/.github/workflows/check_dist.yaml +++ b/.github/workflows/check_dist.yaml @@ -8,7 +8,7 @@ jobs: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 with: fetch-depth: 0 # needed so we can diff properly diff --git a/.github/workflows/pr_toolkit.yml b/.github/workflows/pr_toolkit.yml index 0a5a366..e3b6fa1 100644 --- a/.github/workflows/pr_toolkit.yml +++ b/.github/workflows/pr_toolkit.yml @@ -15,7 +15,7 @@ jobs: runs-on: ubuntu-latest steps: - name: clone local repository - uses: actions/checkout@v4 + uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 - name: run pull-request-toolkit action uses: ./