Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SEC-090: Automated trusted workflow pinning (2024-07-22) #866

Merged
merged 2 commits into from
Jul 24, 2024

Conversation

hashicorp-tsccr[bot]
Copy link
Contributor

Bumping GitHub Actions version to latest TSCCR release.

  • changes in .github/actions/integration-test/action.yml
    • bump actions/download-artifact from v4.1.7 to v4.1.8 (release notes)
    • bump actions/upload-artifact from v4.3.3 to v4.3.4 (release notes)
    • bump actions/upload-artifact from v4.3.3 to v4.3.4 (release notes)
  • changes in .github/workflows/build.yaml
    • bump actions/upload-artifact from v4.3.3 to v4.3.4 (release notes)
    • bump actions/upload-artifact from v4.3.3 to v4.3.4 (release notes)
    • bump actions/download-artifact from v4.1.7 to v4.1.8 (release notes)

This PR was auto-generated by security-tsccr/actions/runs/10035538236

You can alter the configuration of this automation via the hcl config in security-tsccr/automation

This PR can be regenerated by dispatching the GitHub workflow Pin Action Refs. Please reach out to #team-prodsec if you have any questions.

@hashicorp-tsccr hashicorp-tsccr bot requested a review from a team as a code owner July 22, 2024 06:05
@hashicorp-tsccr hashicorp-tsccr bot added the SEC-090/Pinning/Trusted Automated TSCCR pinning PR to trusted SHAs. label Jul 22, 2024
@hashicorp-tsccr hashicorp-tsccr bot force-pushed the tsccr-auto-pinning/trusted/2024-07-22 branch from a12c115 to 382a411 Compare July 22, 2024 07:49
@tvoran
Copy link
Member

tvoran commented Jul 24, 2024

This ended up being

  • actions/setup-go v5.0.1 -> v5.0.2
  • actions/setup-node v4.0.2 -> v4.0.3

@tvoran tvoran added this to the 0.8.1 milestone Jul 24, 2024
@tvoran tvoran merged commit 4979e7e into main Jul 24, 2024
42 checks passed
@tvoran tvoran deleted the tsccr-auto-pinning/trusted/2024-07-22 branch July 24, 2024 22:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
SEC-090/Pinning/Trusted Automated TSCCR pinning PR to trusted SHAs.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant