Skip to content

Pin GitHub Actions to SHA digests (zizmor unpinned-uses) #224

Description

@lhoupert

Pin GitHub Actions to SHA digests

Zizmor detected 3 unpinned-uses findings in .github/workflows/.

GitHub Actions referenced by tag (e.g. actions/checkout@v4) are vulnerable to tag mutation — a compromised or hijacked tag can introduce malicious code into CI runs. Pinning to a full commit SHA (e.g. actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4) eliminates this supply-chain risk.

Fix

Run pin-github-action to update all workflow files automatically:

npx pin-github-action .github/workflows/*.yml

Recommendations

  • Dependabot: Add a .github/dependabot.yml with a github-actions entry so pinned SHAs are updated automatically when new Action versions are released.
  • zizmor-action: Add zizmor-action for continuous workflow security scanning in CI.

References


Opened by ds-security-scanning zizmor-cli-unpinned-uses

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions