Repository navigation
Pin GitHub Actions to commit SHAs #5643
Copy link
Copy link
Closed
Labels
area-buildImprovements in source-build's own build processImprovements in source-build's own build process
Description
Activity
🏷️ Source-build triage pass — 2026-08-19 23:08 UTC
📋 Classification
Field Value Area area-infraAdditional area(s) none Kind feature-request Severity S3 — supply-chain security improvement; no broken scenario today, but unpinned actions are a known security risk Affected version(s) current Repro n/a— feature request, not a bug🚦 Priority
- Blocking: not blocking
- Urgency: ⚪ backlog — no milestone
Security best practice improvement; no active exploit or blocked scenario, can be addressed at next available capacity.
👥 Routing
- Team:
@dotnet/source-build - Possible SME(s): mthalman, ellahathaway
mthalman— issue author; active on infra and release pipeline issues (e.g., Feature band release PRs timing issue #5636, Indicate rebootstrap requirements in source-build release announcements #5639)ellahathaway— active contributor on infra and CI issues in recent months
🔗 Cross-references
- Recommended labels: add
area-infra - Related issues: none found
- Possible duplicate of: none
✅ Assessment
- Confidence: high
- Needs human?: no
Restricted mode — no labels or milestone applied. A maintainer should manually apply any accepted labels and milestone.
- addedarea-buildImprovements in source-build's own build processImprovements in source-build's own build processand removed
on Aug 20, 2026 - linked a pull request that will close this issuePin GitHub Actions to immutable SHAs and enable Dependabot-managed SHA refresh #5644
on Aug 20, 2026
Metadata
Metadata
Labels
area-buildImprovements in source-build's own build processImprovements in source-build's own build process
Type
Projects
- StatusShow more project fieldsDone
For supply-chain security, we should pin the GitHub Actions referenced in the workflows to their commit SHAs. Dependabot can be used to automatically update these commit SHAs with a specified cooldown period.
See example at microsoft/dotnet-framework-docker#1317