ci: pin GitHub Actions to full-length commit SHAs - #1249
Merged
Carter Tinney (cartertinney) merged 2 commits intoAug 31, 2026
Conversation
Copy the security hardening from #1247 onto an internal branch so it can run trusted CI. Co-authored-by: Dan Fiedler <danfiedler@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Preserve the GitHub Actions Dependabot grouping and cooldown while incorporating the newly added upstream configuration. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Avishek (avishekpant)
approved these changes
Aug 31, 2026
Carter Tinney (cartertinney)
deleted the
agents/copy-pr-1247-into-new-branch
branch
August 31, 2026 22:08
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Naturalclar/issue-action@v1.0.0to its full-length commit SHAWhy
Pinning Actions to immutable SHAs improves CI supply-chain security and reproducibility. The cooldown provides time for compromised releases to be detected before Dependabot proposes them.
This reproduces the changes from #1247 on an internal branch so trusted CI can run. Credit to Dan Fiedler (@danfiedler-msft) for the original contribution.
Validation
596dfb92b8ba81449d4b3a0f34e9d3d279fab330is the commit referenced byNaturalclar/issue-actiontagv1.0.0