Skip to content

Pin slsa-framework/slsa-github-generator action with a tag#46

Merged
dastrong merged 2 commits into
mainfrom
dastrong/pin-slsa-action
May 13, 2025
Merged

Pin slsa-framework/slsa-github-generator action with a tag#46
dastrong merged 2 commits into
mainfrom
dastrong/pin-slsa-action

Conversation

@dastrong
Copy link
Copy Markdown
Collaborator

What problem are you trying to solve?

The release workflow is failing due to us pinning the version of slsa-framework/slsa-github-generator with a commit instead of a tag.

What is your solution?

Pin with v2.0.0 which is a revert of this change

@dastrong dastrong requested a review from a team as a code owner May 12, 2025 22:41
@datadog-datadog-prod-us1
Copy link
Copy Markdown

datadog-datadog-prod-us1 Bot commented May 12, 2025

Datadog Summary

✅ Code Quality    ❌ Code Security

Next Steps

Fix this code security issue introduced by this PR:

🔴 High: github-actions/unpinned-actions
.github/workflows/goreleaser.yml:79

Workflow depends on unpinned GitHub Actions


Was this helpful? Give us feedback!

Comment thread .github/workflows/goreleaser.yml
@github-actions
Copy link
Copy Markdown

Go test coverage report

Total test coverage: 90.8% (3602/3966)

Current tests coverage has not changed.

jbcibois-ddhq
jbcibois-ddhq previously approved these changes May 13, 2025
@dastrong dastrong force-pushed the dastrong/pin-slsa-action branch 3 times, most recently from 214c5bc to 9613acc Compare May 13, 2025 16:11
@dastrong dastrong merged commit 7ca926d into main May 13, 2025
35 of 39 checks passed
@dastrong dastrong deleted the dastrong/pin-slsa-action branch May 13, 2025 16:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants