8000 Pin GitHub Pipeline Action Dependencies and specify reduced pipeline permissions by J12934 · Pull Request #3229 · secureCodeBox/secureCodeBox · GitHub
[go: up one dir, main page]

Skip to content

Conversation

@J12934
Copy link
Member
@J12934 J12934 commented Aug 22, 2025

Description

Following best practices recommended by github: https://docs.github.com/en/actions/reference/security/secure-use#using-third-party-actions

Trying to improve the OSS Scorecard rating a bit.
https://scorecard.dev/viewer/?uri=github.com/secureCodeBox/secureCodeBox

Checklist

  • Test your changes as thoroughly as possible before you commit them. Preferably, automate your test by unit/integration tests.
  • Make sure that all your commits are signed-off and that you are added to the Contributors file.
  • Make sure that all CI finish successfully.
  • Optional (but appreciated): Make sure that all commits are Verified.

Following best practices recommended by github: https://docs.github.com/en/actions/reference/security/secure-use#using-third-party-actions

Signed-off-by: Jannik Hollenbach <jannik.hollenbach@iteratec.com>
@netlify
Copy link
netlify bot commented Aug 22, 2025

Deploy Preview for docs-securecodebox canceled.

Name Link
🔨 Latest commit 9854fc8
🔍 Latest deploy log https://app.netlify.com/projects/docs-securecodebox/deploys/68a8679426ef5c0008bbacdc

Signed-off-by: Jannik Hollenbach <jannik.hollenbach@iteratec.com>
@J12934 J12934 changed the title Pin GitHub Pipeline Action Dependencies Pin GitHub Pipeline Action Dependencies and specify reduced pipeline permissions Aug 22, 2025
@sonarqubecloud
Copy link

@github-project-automation github-project-automation bot moved this from Triage to Reviewer Approved in secureCodeBox Aug 25, 2025
@Reet00 Reet00 merged commit a7ea1a3 into secureCodeBox:main Aug 25, 2025
85 of 86 checks passed
@github-project-automation github-project-automation bot moved this from Reviewer Approved to Done in secureCodeBox Aug 25, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

2 participants

0