4 ms·
Sure, but then again the link you sent says: `Pin actions to a tag only if you trust the creator` If I don't trust GitHub, why am I storing my source code on i
by Arbortheus 3y ago
Sure, but then again the link you sent says: `Pin actions to a tag only if you trust the creator`
If I don't trust GitHub, why am I storing my source code on it and running CI via GitHub actions?
There are also some security gains from ranged pinning. Suppose I pin my library to `1.1.x` instead of `1.1.0`, when a security patch comes along for some CVE, my service will automatically run the `1.1.1` patch release the next time we deploy it.
I would say the likelihood of a developer getting lazy and not bumping a dependency causing a security incident is higher than a supply chain attack if you're already using reputable libraries.
Let's be frank, how many developers care enough to go into the 10 repos they've ended up owning to go and change their `actions/checkout@v3.1.6` to `actions/checkout@v3.1.7`.