Skip to content

Commit 5e42a0b

Browse files
fix: use pinned SHA for actions/checkout instead of version tag
Address security best practice by using pinned commit SHA 692973e3d937129bcbf40652eb9f2f61becf3332 instead of actions/checkout@v4 version tag. Co-Authored-By: Patrick Kaeding <[email protected]>
1 parent e07d652 commit 5e42a0b

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

.github/workflows/dependency-scan.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ jobs:
1010
generate-nodejs-sbom:
1111
runs-on: ubuntu-latest
1212
steps:
13-
- uses: actions/checkout@v4
13+
- uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4
1414

1515
- name: Generate SBOM
1616
uses: launchdarkly/gh-actions/actions/dependency-scan/generate-sbom@main
@@ -22,7 +22,7 @@ jobs:
2222
needs:
2323
- generate-nodejs-sbom
2424
steps:
25-
- uses: actions/checkout@v4
25+
- uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4
2626

2727
- name: Evaluate SBOM Policy
2828
uses: launchdarkly/gh-actions/actions/dependency-scan/evaluate-policy@main

0 commit comments

Comments
 (0)