Skip to content

Pin actions/cache by SHA#480

Merged
simar7 merged 1 commit intoaquasecurity:masterfrom
martincostello:patch-1
Aug 22, 2025
Merged

Pin actions/cache by SHA#480
simar7 merged 1 commit intoaquasecurity:masterfrom
martincostello:patch-1

Conversation

@martincostello
Copy link
Contributor

Resolves #479.

Copilot AI review requested due to automatic review settings August 16, 2025 08:30
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates the GitHub Actions workflow to pin the actions/cache action by its SHA hash instead of using a version tag, improving security by preventing potential tag manipulation attacks.

  • Replaces the version tag v4 with a specific SHA hash for actions/cache@v4.2.4

Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.

Copy link
Member

@simar7 simar7 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks!

@simar7 simar7 merged commit c26e17b into aquasecurity:master Aug 22, 2025
2 checks passed
@martincostello martincostello deleted the patch-1 branch August 22, 2025 21:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Action is not compatible with enforced action pinning

2 participants

Comments