-
Type:
Task
-
Resolution: Done
-
Priority:
Unknown
-
None
-
Affects Version/s: None
-
Component/s: None
-
None
Context
Only recently github allowed releases to be immutable, by default actions are mutable even when specifying a version.
- https://github.com/mongodb/mongo-go-driver/security/code-scanning/110
- https://github.com/mongodb/mongo-go-driver/security/code-scanning/166
- https://github.com/mongodb/mongo-go-driver/security/code-scanning/165
- https://github.com/mongodb/mongo-go-driver/security/code-scanning/164
- https://github.com/mongodb/mongo-go-driver/security/code-scanning/163
- https://github.com/mongodb/mongo-go-driver/security/code-scanning/162
- https://github.com/mongodb/mongo-go-driver/security/code-scanning/150
- https://github.com/mongodb/mongo-go-driver/security/code-scanning/145
- https://github.com/mongodb/mongo-go-driver/security/code-scanning/144
- https://github.com/mongodb/mongo-go-driver/security/code-scanning/142
- https://github.com/mongodb/mongo-go-driver/security/code-scanning/141
- https://github.com/mongodb/mongo-go-driver/security/code-scanning/140
- https://github.com/mongodb/mongo-go-driver/security/code-scanning/139
- https://github.com/mongodb/mongo-go-driver/security/code-scanning/138
- https://github.com/mongodb/mongo-go-driver/security/code-scanning/137
- https://github.com/mongodb/mongo-go-driver/security/code-scanning/136
- https://github.com/mongodb/mongo-go-driver/security/code-scanning/135
- https://github.com/mongodb/mongo-go-driver/security/code-scanning/134
- https://github.com/mongodb/mongo-go-driver/security/code-scanning/133
- https://github.com/mongodb/mongo-go-driver/security/code-scanning/132
- https://github.com/mongodb/mongo-go-driver/security/code-scanning/131
- https://github.com/mongodb/mongo-go-driver/security/code-scanning/130
- https://github.com/mongodb/mongo-go-driver/security/code-scanning/123
Definition of done
Pin github action steps to hashes for their release to prevent any potential attacks hidden in github actions.
- is related to
-
GODRIVER-3968 [Before next minor release] Orphaned Release Tag Caused by Unset dry_run Input in pre-publish
-
- Needs Triage
-