Skip to content

Hash specification of external GitHub Actions#35

Merged
tomtwinkle merged 1 commit intomainfrom
enhancement/hash-specification-of-external-github-actions
Apr 2, 2025
Merged

Hash specification of external GitHub Actions#35
tomtwinkle merged 1 commit intomainfrom
enhancement/hash-specification-of-external-github-actions

Conversation

@tomtwinkle
Copy link
Copy Markdown
Owner

CVE-2025-30066
If malicious changes are made to an external GHA and it is released in the same version, the GHA will run using the version with the malicious changes.
Specify the commit hash explicitly to avoid unintended module downloads.

use https://github.com/suzuki-shunsuke/pinact

@tomtwinkle tomtwinkle merged commit f4069bc into main Apr 2, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant