Skip to content

Apply GitHub Actions security policies - #85

Merged
brhoades merged 2 commits into
mainfrom
chore/GHA-281902-stepsecurity-remediation
Jul 28, 2026
Merged

Apply GitHub Actions security policies#85
brhoades merged 2 commits into
mainfrom
chore/GHA-281902-stepsecurity-remediation

Conversation

@stepsecurity-app

Copy link
Copy Markdown
Contributor

Note

This is an automated PR. It is the team's responsibility to review it, test its accuracy, and ensure all checks pass. If any checks aren't passing, please push changes to this branch.

Summary

This pull request has been generated by StepSecurity based on our GitHub Actions Policy. Please review and merge this to apply these security controls.

Use #wg-supply-chain-security for questions or follow-up!

Security Fixes

Harden Runner

Harden-Runner is an open-source security agent for the GitHub-hosted runner to prevent software supply chain attacks. It prevents exfiltration of credentials, detects tampering of source code during build, and enables running jobs without sudo access.

Pinned Dependencies

Pinning GitHub Actions to specific versions or commit SHAs ensures that your workflows remain consistent and secure.
Unpinned actions can lead to unexpected changes or vulnerabilities caused by upstream updates.

StepSecurity Maintained Actions

Risky GitHub Actions can expose your project to potential security risks. Risky actions have been replaced with StepSecurity maintained actions, that are secure drop-in replacements.

Keeping your actions up to date with Dependabot

With Dependabot version updates, when Dependabot identifies an outdated dependency, it raises a pull request to update the manifest to the latest version of the dependency. This is recommended by GitHub as well as The Open Source Security Foundation (OpenSSF).

Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
@CLAassistant

CLAassistant commented Jul 28, 2026

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you all sign our Contributor License Agreement before we can accept your contribution.
1 out of 2 committers have signed the CLA.

✅ RebeccaMahany
❌ stepsecurity-app[bot]
You have signed the CLA already but the status is still pending? Let us recheck it.

@brhoades brhoades left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@brhoades
brhoades merged commit 26840f1 into main Jul 28, 2026
15 of 16 checks passed
@brhoades
brhoades deleted the chore/GHA-281902-stepsecurity-remediation branch July 28, 2026 21:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants