Skip to content

[repo] GitHub Actions hardening#621

Merged
Kielek merged 1 commit into
signalfx:mainfrom
Kielek:repo-pin-gh-actions
Apr 2, 2025
Merged

[repo] GitHub Actions hardening#621
Kielek merged 1 commit into
signalfx:mainfrom
Kielek:repo-pin-gh-actions

Conversation

@Kielek
Copy link
Copy Markdown
Contributor

@Kielek Kielek commented Mar 31, 2025

Similar PR for contrib open-telemetry/opentelemetry-dotnet-contrib#2671

Changes

Preventing problems similar to https://www.cisa.gov/news-events/alerts/2025/03/18/supply-chain-compromise-third-party-tj-actionschanged-files-cve-2025-30066-and-reviewdogaction
In the upstream repository we have such configuration for a while.

@Kielek Kielek requested review from a team as code owners March 31, 2025 17:55
@Kielek Kielek merged commit e5911a4 into signalfx:main Apr 2, 2025
@Kielek Kielek deleted the repo-pin-gh-actions branch April 2, 2025 04:27
@github-actions github-actions Bot locked and limited conversation to collaborators Apr 2, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants