Skip to content

Pin GitHub Actions to commit SHAs #5643

Description

@mthalman

For supply-chain security, we should pin the GitHub Actions referenced in the workflows to their commit SHAs. Dependabot can be used to automatically update these commit SHAs with a specified cooldown period.

See example at microsoft/dotnet-framework-docker#1317

Activity

  1. github-actions commented on Aug 19, 2026

    @github-actions
    🏷️ Source-build triage pass — 2026-08-19 23:08 UTC

    📋 Classification

    Field Value
    Area area-infra
    Additional area(s) none
    Kind feature-request
    Severity S3 — supply-chain security improvement; no broken scenario today, but unpinned actions are a known security risk
    Affected version(s) current
    Repro n/a — feature request, not a bug

    🚦 Priority

    • Blocking: not blocking
    • Urgency: ⚪ backlog — no milestone

      Security best practice improvement; no active exploit or blocked scenario, can be addressed at next available capacity.

    👥 Routing

    🔗 Cross-references

    • Recommended labels: add area-infra
    • Related issues: none found
    • Possible duplicate of: none

    ✅ Assessment

    • Confidence: high
    • Needs human?: no

    Restricted mode — no labels or milestone applied. A maintainer should manually apply any accepted labels and milestone.

    Generated by Triage · 65.7 AIC · ⌖ 11.1 AIC · ⊞ 24.6K · ◷

  2. added
    area-buildImprovements in source-build's own build process
    and removed on Aug 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

area-buildImprovements in source-build's own build process

Type

No type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions