3 ms·
Yeah, only works if all used Actions would use SHAs too, which is not the case. Positive example: https://github.com/codecov/codecov-action/blob/96b38e9e60ee60
by Kovah 10mo ago
Yeah, only works if all used Actions would use SHAs too, which is not the case.
Positive example: https://github.com/codecov/codecov-action/blob/96b38e9e60ee60a8c3911f4612407bba2f9195fb/action.yml#L233 https://github.com/codecov/codecov-action/blob/96b38e9e60ee6...
Negative example: https://github.com/armbian/build/blob/54808ecff253fb71615161e3a216ad14b420022b/action.yml#L101 https://github.com/armbian/build/blob/54808ecff253fb71615161...
- cedws 10mo agoI've also found many Actions that do other dodgy stuff, like pulling and executing unpinned scripts from external websites, or installing unpinned binaries from GitHub releases. Pinning an Action isn't enough, you have to audit it.