Conversation
Replaces mutable version tags with locked commit SHAs to prevent supply chain attacks from compromised or force-pushed tags.
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
anxolin
left a comment
There was a problem hiding this comment.
Approved. The hash matches the expected versions
Just a small comment. The publish.yml workflow pins to actions/checkout@v3 while all other workflows use @v4. This was already the case before this PR (not introduced by it), but could be bumped to v4 in a follow-up.
Summary
@v4) with locked commit SHAs