Skip to content

Chore: Pin GitHub Actions#8582

Open
pieterocp wants to merge 1 commit into
primefaces:masterfrom
pieterocp:pin-all-actions
Open

Chore: Pin GitHub Actions#8582
pieterocp wants to merge 1 commit into
primefaces:masterfrom
pieterocp:pin-all-actions

Conversation

@pieterocp
Copy link
Copy Markdown

@pieterocp pieterocp commented May 22, 2026

To prevent malicious commits being pushed upstream impacting this project.

As well as removing a couple of broken actions post-hack.

See https://www.stepsecurity.io/blog/pinning-github-actions-for-enhanced-security-a-complete-guide for more about why/how.

Defect Fixes

It's GitHub actions, it's not something that will have a visible impact to the library.

Feature Requests

Due to company policy, we are unable to accept feature request PRs with significant changes as such cases has to be implemented by our team following our own processes.

I didn't find a security policy, but I assume we don't want to run malware and have tokens exfiltrated.

…g this project)

(and remove a couple of broken actions post-hack)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant