ci: pin actions to commit hashes#259
Conversation
Replaces mutable version tags with locked commit SHAs to prevent supply chain attacks from compromised or force-pushed tags.
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
Summary
@v4) with locked commit SHAs