Skip to content

chore(security): pin reusable publish workflow SHA (mini shai-hulud)#4

Merged
nmccready merged 1 commit into
masterfrom
chore/harden-publish-shai-hulud
May 13, 2026
Merged

chore(security): pin reusable publish workflow SHA (mini shai-hulud)#4
nmccready merged 1 commit into
masterfrom
chore/harden-publish-shai-hulud

Conversation

@nmccready

Copy link
Copy Markdown

Summary

Pins the org-wide reusable publish + tests workflow refs from `@main` to commit SHA `3c0bca8` to defeat tag/branch-rewrite attacks vs Mini Shai-Hulud (2026-05-11).

Companion to brickhouse-tech/.github#7 (which hardens the actual reusable workflow). After that PR merges, follow up here to bump pin SHA and inherit hardening.

Test plan

🤖 Generated with Claude Code

Pin brickhouse-tech/.github reusable workflow refs from @main to commit
SHA 3c0bca8 to defeat tag-rewrite attacks, vs Mini Shai-Hulud npm
supply-chain campaign (2026-05-11). Follow-up to bump to new SHA after
brickhouse-tech/.github hardening PR merges.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@nmccready nmccready enabled auto-merge May 12, 2026 19:55

@nmccready nmccready left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants