-
Type:
Sub-task
-
Resolution: Unresolved
-
Priority:
Unknown
-
None
-
Affects Version/s: None
-
Component/s: None
-
0
-
None
-
None
-
None
-
None
-
None
-
None
-
None
Pin every uses: reference in mongodb-client-encryption to a full 40-character commit SHA, keeping the version as a trailing comment.
This is the repo where Semgrep raised the finding, on PR #137.
Current inventory across .github/workflows: 12 actions/checkout@v6, 6 actions/setup-node@v6, 4 docker/setup-qemu-action@v3, 4 docker/setup-buildx-action@v3, 3 actions/upload-artifact@v7, 1 actions/download-artifact@v7, 2 github/codeql-action@v4, 1 googleapis/release-please-action@v4, and 5 mongodb-labs/drivers-github-tools/*@v3.
Implementation Requirements
- Cover build.yml, test.yml, release.yml, lint.yml, codeql.yml and webpack.yml
- Confirm dependabot is configured to bump pinned SHAs
Testing Requirements
- All workflows pass after pinning