Pin GitHub Actions to commit SHAs in mongodb-client-encryption

XMLWordPrintableJSON

    • Type: Sub-task
    • Resolution: Unresolved
    • Priority: Unknown
    • None
    • Affects Version/s: None
    • Component/s: None
    • 0
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Pin every uses: reference in mongodb-client-encryption to a full 40-character commit SHA, keeping the version as a trailing comment.

      This is the repo where Semgrep raised the finding, on PR #137.

      Current inventory across .github/workflows: 12 actions/checkout@v6, 6 actions/setup-node@v6, 4 docker/setup-qemu-action@v3, 4 docker/setup-buildx-action@v3, 3 actions/upload-artifact@v7, 1 actions/download-artifact@v7, 2 github/codeql-action@v4, 1 googleapis/release-please-action@v4, and 5 mongodb-labs/drivers-github-tools/*@v3.

      Implementation Requirements

      • Cover build.yml, test.yml, release.yml, lint.yml, codeql.yml and webpack.yml
      • Confirm dependabot is configured to bump pinned SHAs

      Testing Requirements

      • All workflows pass after pinning

            Assignee:
            Unassigned
            Reporter:
            Sergey Zelenov
            None
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated: