Skip to content

Require GitHub Actions to be pinned to hashes#14

Open
fniessink wants to merge 1 commit into
mainfrom
github-actions-policy
Open

Require GitHub Actions to be pinned to hashes#14
fniessink wants to merge 1 commit into
mainfrom
github-actions-policy

Conversation

@fniessink
Copy link
Copy Markdown
Member

If a repository uses Github Actions, the versions of the actions are pinned to specific commits (rather than tags or branches, which are mutable). This is enforced for ICTU repositories by the GitHub general actions permission "Require actions to be pinned to a full-length commit SHA".

If a repository uses Github Actions, the versions of the actions are pinned to specific commits (rather than tags or branches, which are mutable). This is enforced for ICTU repositories by the GitHub general actions permission "Require actions to be pinned to a full-length commit SHA".
@fniessink
Copy link
Copy Markdown
Member Author

fniessink commented May 27, 2026

@ICTU/everyone Let op: we gaan per 15 juni voor ICTU GitHub repositories verplichten dat GitHub Actions gepind zijn op commit hashes (zie https://nldesignsystem.nl/handboek/developer/github-actions/). Mocht je meer tijd of hulp nodig hebben, laat het me weten.

Dit is uiteraard alleen van toepassing als je repository gebruik maakt van GitHub Actions.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant