Skip to content

chore(SEC-401): pin GitHub Actions to commit SHAs#20

Open
tingram1k5 wants to merge 1 commit into
mainfrom
feat/SEC-401/pin-github-actions-shas
Open

chore(SEC-401): pin GitHub Actions to commit SHAs#20
tingram1k5 wants to merge 1 commit into
mainfrom
feat/SEC-401/pin-github-actions-shas

Conversation

@tingram1k5
Copy link
Copy Markdown

Pins references under .github/workflows to commit SHAs using frizbee.

Why: Reduces supply-chain risk by fixing action contents to an immutable revision instead of a moving tag or branch.

Pin action tags and branches to immutable commit SHAs for supply-chain security.
@complianator-bot
Copy link
Copy Markdown

Metadata Validation Result

FYI: your catalog-info.yaml contains errors.

Why is this popping up?
  • We want to ensure each software and infrastructure component in the 1K5 org is catalogued.
  • This helps us to better identify ownership, understand relations and resolve incidents.
  • Therefore, each repository must contain a catalog-info.yaml that includes a description, type, owner, lifecycle and corresponding system.
  • The Complianator Bot informs teams about missing / invalid properties in their catalog-info.yaml in Pull Requests (right now, only as a non-breaking warning).
  • You can find a list of your team's components in DevHub.
  • Check the metadata guide for detailed information
Line number (click to edit) Error ToDo
0 catalog-info..yaml missing.` Please create a valid catalog-info.yaml following this documentation.

@gemini-code-assist
Copy link
Copy Markdown

Note

Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant