Skip to content

Pin GitHub Actions to immutable SHAs - #2602

Open
javier20dev25 wants to merge 1 commit into
modelcontextprotocol:mainfrom
javier20dev25:sentinel/security-audit-202608020701
Open

Pin GitHub Actions to immutable SHAs#2602
javier20dev25 wants to merge 1 commit into
modelcontextprotocol:mainfrom
javier20dev25:sentinel/security-audit-202608020701

Conversation

@javier20dev25

@javier20dev25 javier20dev25 commented Aug 2, 2026

Copy link
Copy Markdown

This PR replaces mutable GitHub Action tags with immutable commit SHAs across 8 workflow files.

Affected workflows:

  • .github/workflows/claude.yml
  • .github/workflows/conformance.yml
  • .github/workflows/deploy-docs.yml
  • .github/workflows/examples.yml
  • .github/workflows/main.yml
  • .github/workflows/publish.yml
  • .github/workflows/release.yml
  • .github/workflows/update-spec-types.yml

No behavioral changes expected. Only immutable SHA pinning and hardening fixes.


Prepared with Sentinel after manual review.

Generated by Sentinel security research. Evidence in the PR description.
@javier20dev25
javier20dev25 requested a review from a team as a code owner August 2, 2026 07:02
@changeset-bot

changeset-bot Bot commented Aug 2, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 0ceb10b

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@pkg-pr-new

pkg-pr-new Bot commented Aug 2, 2026

Copy link
Copy Markdown

Open in StackBlitz

@modelcontextprotocol/client

npm i https://pkg.pr.new/@modelcontextprotocol/client@2602

@modelcontextprotocol/codemod

npm i https://pkg.pr.new/@modelcontextprotocol/codemod@2602

@modelcontextprotocol/core

npm i https://pkg.pr.new/@modelcontextprotocol/core@2602

@modelcontextprotocol/server

npm i https://pkg.pr.new/@modelcontextprotocol/server@2602

@modelcontextprotocol/server-legacy

npm i https://pkg.pr.new/@modelcontextprotocol/server-legacy@2602

@modelcontextprotocol/express

npm i https://pkg.pr.new/@modelcontextprotocol/express@2602

@modelcontextprotocol/fastify

npm i https://pkg.pr.new/@modelcontextprotocol/fastify@2602

@modelcontextprotocol/hono

npm i https://pkg.pr.new/@modelcontextprotocol/hono@2602

@modelcontextprotocol/node

npm i https://pkg.pr.new/@modelcontextprotocol/node@2602

commit: 0ceb10b

@javier20dev25 javier20dev25 changed the title Sentinel: harden CI/CD (29 best practices) Pin GitHub Actions to immutable SHAs Aug 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant