3 ms·
This is correct, using a commit hash is safer. However, you'll sometimes want to update the commit hash after the action's maintainer releases new code. If you
by robbya 7y ago
This is correct, using a commit hash is safer.
However, you'll sometimes want to update the commit hash after the action's maintainer releases new code. If you don't then you run the risk of running an old action that has vulnerable components or bugs.
The easiest workflow for that should be Dependabot's updater for GitHub actions:
https://dependabot.com/github-actions/ https://dependabot.com/github-actions/
Has anyone tried that approach for GitHub actions?
You still need to review the action's code before you use it, and every time you update to a new commit hash. But this approach protects you from automatically running new malicious code pushed to master/re-tagged.