Skip to content

[DEV-72] chore: pin GitHub Actions to commit SHAs#133

Closed
austinpray-mixpanel wants to merge 2 commits into
masterfrom
pin-actions-to-sha
Closed

[DEV-72] chore: pin GitHub Actions to commit SHAs#133
austinpray-mixpanel wants to merge 2 commits into
masterfrom
pin-actions-to-sha

Conversation

@austinpray-mixpanel

@austinpray-mixpanel austinpray-mixpanel commented Mar 24, 2026

Copy link
Copy Markdown
Member

Summary

Pin all GitHub Actions workflow steps to immutable full commit SHAs instead of mutable tags or branches.

Why

Mutable tags can be moved after the fact, making it possible for a supply-chain attack to inject malicious code into CI. Pinning to a commit SHA ensures the exact version of an action is used, and the original tag is preserved as an inline comment for readability.

Verification

Review the diff — all uses: lines with third-party actions should now reference a 40-character commit SHA with the original tag as an inline comment.

🤖 Generated with Claude Code

Linear: https://linear.app/mixpanel/issue/DEV-72/pin-all-github-actions-to-commit-shas

@austinpray-mixpanel austinpray-mixpanel requested review from a team and ketanmixpanel March 24, 2026 03:46
@codecov

codecov Bot commented Mar 24, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 96.64%. Comparing base (a780e93) to head (cabda15).

Additional details and impacted files
@@           Coverage Diff           @@
##           master     #133   +/-   ##
=======================================
  Coverage   96.64%   96.64%           
=======================================
  Files          14       14           
  Lines         655      655           
=======================================
  Hits          633      633           
  Misses         22       22           
Flag Coverage Δ
openfeature 100.00% <0.00%> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@austinpray-mixpanel austinpray-mixpanel requested review from a team, grodr and krishna16v and removed request for a team March 24, 2026 14:04
@austinpray-mixpanel austinpray-mixpanel changed the title chore: pin GitHub Actions to commit SHAs [DEV-72] chore: pin GitHub Actions to commit SHAs Mar 24, 2026
@linear

linear Bot commented Mar 24, 2026

Copy link
Copy Markdown

@gmasnica gmasnica self-requested a review March 24, 2026 23:11
@gmasnica gmasnica removed the request for review from krishna16v March 24, 2026 23:18
@jinhyoo-mp jinhyoo-mp closed this May 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants