Skip to content

Commit e0d04b8

Browse files
committed
Pin GitHub Actions to specific commit SHAs for security
1 parent 1752522 commit e0d04b8

2 files changed

Lines changed: 7 additions & 7 deletions

File tree

.github/workflows/changesets.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -16,13 +16,13 @@ jobs:
1616
pull-requests: write
1717
steps:
1818
- name: Checkout
19-
uses: actions/checkout@v4
19+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
2020

2121
- name: Setup pnpm
22-
uses: pnpm/action-setup@v4
22+
uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061 # v4
2323

2424
- name: Setup Node.js
25-
uses: actions/setup-node@v4
25+
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
2626
with:
2727
node-version: 22
2828
cache: 'pnpm'
@@ -31,7 +31,7 @@ jobs:
3131
run: pnpm install --frozen-lockfile
3232

3333
- name: Create Release PR
34-
uses: changesets/action@v1
34+
uses: changesets/action@e0145edc7d9d8679003495b11f87bd8ef63c0cba # v1.5.3
3535
with:
3636
version: pnpm changeset version
3737
title: 'chore: version packages'

.github/workflows/publish.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ jobs:
2626
id-token: write # Required for npm OIDC trusted publishers
2727
steps:
2828
- name: Checkout
29-
uses: actions/checkout@v4
29+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
3030

3131
- name: Determine release type
3232
id: release-type
@@ -58,10 +58,10 @@ jobs:
5858
fi
5959
6060
- name: Setup pnpm
61-
uses: pnpm/action-setup@v4
61+
uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061 # v4
6262

6363
- name: Setup Node.js
64-
uses: actions/setup-node@v4
64+
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
6565
with:
6666
node-version: 22
6767
cache: 'pnpm'

0 commit comments

Comments
 (0)