Skip to content

Actions must be pinned to a full-length commit SHA #4440

@amilcarlucas

Description

@amilcarlucas

Describe the bug
Security best practices dictate that githuib repositories should activate the feature:
"Require actions to be pinned to a full-length commit SHA "

All the actions I use continue to run after activating that setting except:
4876e96

To Reproduce
Use
4876e96

Activate Settings > Actions > General > Action permissions > "Require actions to be pinned to a full-length commit SHA "

Github will refuse to run the action because it does not pin it's internal dependencies.

Expected behavior
It should just work

Have you ever heard of dependabot? or renovate?

Metadata

Metadata

Assignees

No one assigned

    Labels

    status:triageIssue that has not been triagedtype:bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions