Skip to content

[DEV-72] chore: pin GitHub Actions to commit SHAs#133

Open
austinpray-mixpanel wants to merge 1 commit intomasterfrom
pin-actions-to-sha
Open

[DEV-72] chore: pin GitHub Actions to commit SHAs#133
austinpray-mixpanel wants to merge 1 commit intomasterfrom
pin-actions-to-sha

Conversation

@austinpray-mixpanel
Copy link
Copy Markdown
Member

@austinpray-mixpanel austinpray-mixpanel commented Mar 24, 2026

Summary

Pin all GitHub Actions workflow steps to immutable full commit SHAs instead of mutable tags or branches.

Why

Mutable tags can be moved after the fact, making it possible for a supply-chain attack to inject malicious code into CI. Pinning to a commit SHA ensures the exact version of an action is used, and the original tag is preserved as an inline comment for readability.

Verification

Review the diff — all uses: lines with third-party actions should now reference a 40-character commit SHA with the original tag as an inline comment.

🤖 Generated with Claude Code

Linear: https://linear.app/mixpanel/issue/DEV-72/pin-all-github-actions-to-commit-shas

@austinpray-mixpanel austinpray-mixpanel requested review from a team and ketanmixpanel March 24, 2026 03:46
@codecov
Copy link
Copy Markdown

codecov bot commented Mar 24, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 96.29%. Comparing base (a3020d2) to head (853b8a5).

Additional details and impacted files
@@           Coverage Diff           @@
##           master     #133   +/-   ##
=======================================
  Coverage   96.29%   96.29%           
=======================================
  Files          12       12           
  Lines         567      567           
=======================================
  Hits          546      546           
  Misses         21       21           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@austinpray-mixpanel austinpray-mixpanel requested review from a team, grodr and krishna16v and removed request for a team March 24, 2026 14:04
@austinpray-mixpanel austinpray-mixpanel changed the title chore: pin GitHub Actions to commit SHAs [DEV-72] chore: pin GitHub Actions to commit SHAs Mar 24, 2026
@linear
Copy link
Copy Markdown

linear bot commented Mar 24, 2026

@gmasnica gmasnica self-requested a review March 24, 2026 23:11
@gmasnica gmasnica removed the request for review from krishna16v March 24, 2026 23:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants