Skip to content

CLOUD-410 ktlo: pin GitHub actions to commit SHAs#4

Merged
MorrisJobke merged 1 commit into
masterfrom
ktlo/pin-gh-actions
May 13, 2026
Merged

CLOUD-410 ktlo: pin GitHub actions to commit SHAs#4
MorrisJobke merged 1 commit into
masterfrom
ktlo/pin-gh-actions

Conversation

@desouradeep

@desouradeep desouradeep commented May 12, 2026

Copy link
Copy Markdown
Contributor

Action required from the owning team: please review and merge this PR. It was opened as part of an org-wide rollout for CLOUD-410; the Cloud team is not merging on your behalf.

Summary

Pins all external GitHub Actions in this repo from mutable tags (e.g. @v4) to immutable commit SHAs, and ensures dependabot is configured to keep them updated.

Improves supply-chain security per CLOUD-410. Each pinned line keeps the original tag as a trailing comment for readability.

  • Jimdo-owned actions (Jimdo/…) are intentionally not pinned (out of scope per the ticket).
  • Local actions (./...) are untouched.
  • Dependabot is configured (or updated) to track github-actions monthly, on the 1st of each month, at a hour staggered between 09:00–15:00 Europe/Berlin (one fixed hour per repo). A 3-day cooldown filters out brand-new releases.

Test plan

  • CI passes
  • No unintended changes outside .github/

@desouradeep desouradeep added the cloud-410 CLOUD-410: pin GitHub actions to commit SHAs label May 12, 2026
@desouradeep desouradeep changed the title ktlo: pin GitHub actions to commit SHAs CLOUD-410 ktlo: pin GitHub actions to commit SHAs May 12, 2026
@MorrisJobke MorrisJobke marked this pull request as ready for review May 13, 2026 07:52
@MorrisJobke MorrisJobke merged commit db8e7f3 into master May 13, 2026
3 checks passed
@MorrisJobke MorrisJobke deleted the ktlo/pin-gh-actions branch May 13, 2026 07:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cloud-410 CLOUD-410: pin GitHub actions to commit SHAs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants