Skip to content

Pin GitHub Actions to commit SHAs - #380

Merged
paulinebm merged 1 commit into
mainfrom
security/pin-actions-to-sha
Sep 23, 2026
Merged

paulinebm merged 1 commit into
mainfrom
security/pin-actions-to-sha

Conversation

@hf-security-analysis

Copy link
Copy Markdown
Contributor

Workflow hardening

Actions pinned to commit SHAs

A version tag is mutable. Whoever controls an action's repository can move v4
to different code, and every workflow referencing @v4 picks that up on the
next run with nothing to review. That is how tj-actions/changed-files shipped
a credential dumper to thousands of repositories in March 2025.

Pinning to a full commit SHA freezes the code that runs. The version tag stays
on the line as a comment, so the reference is still readable.

This pins, it does not upgrade. Every SHA below is the commit the tag
already resolves to today, so nothing about what your CI executes changes — it
only removes the ability for it to change without your knowing.

Workflow Before After
.github/workflows/pip.yml - uses: actions/checkout@v3 - uses: actions/checkout@a37ce9120846195fa4ece8f58b268e6043cb2f26 # v3.7.0
.github/workflows/pip.yml - uses: actions/setup-python@v4 - uses: actions/setup-python@7f4fc3e22c37d6ff65e88745f38bd3157c663f7c # v4.9.1
.github/workflows/quality.yml - uses: actions/checkout@v2 - uses: actions/checkout@0717577d45739eb3c851188b29f50ed6c0b2194e # v2.8.0
.github/workflows/quality.yml uses: actions/setup-python@v3 uses: actions/setup-python@3542bca2639a428e1796aaa6a2ffef0c0f575566 # v3.1.4
.github/workflows/tests.yml - uses: actions/checkout@v3 - uses: actions/checkout@a37ce9120846195fa4ece8f58b268e6043cb2f26 # v3.7.0
.github/workflows/tests.yml uses: actions/setup-python@v4 uses: actions/setup-python@7f4fc3e22c37d6ff65e88745f38bd3157c663f7c # v4.9.1
.github/workflows/tests.yml - uses: actions/cache@v3 - uses: actions/cache@6f8efc29b200d32929f49075959781ed54ec270c # v3.5.0
.github/workflows/wheels.yml - uses: pypa/cibuildwheel@v2.10.1 - uses: pypa/cibuildwheel@225387a9d55a3df0ca48efc17acf4964b8ef4f10 # v2.10.1
.github/workflows/wheels.yml - uses: pypa/gh-action-pypi-publish@v1.5.1 - uses: pypa/gh-action-pypi-publish@37f50c210e3d2f9450da2cd423303d6a14a6e29f # v1.5.1

Opened by the workflow security bot. It changes what this pull request says it
changes, and nothing else.

A tag is mutable: whoever controls the action's repository can move
`v4` to different code, and the next run picks it up with no diff to
review. Pinning to the commit SHA freezes the code that runs today.
@paulinebm
paulinebm merged commit e2662c8 into main Sep 23, 2026
3 of 21 checks passed
@paulinebm
paulinebm deleted the security/pin-actions-to-sha branch September 23, 2026 14:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant