Actions should be pinned to a full-length commit SHA
Last updated
Last updated
This check passes if the tag for each Action in the job is a full-length commit SHA.
Reduces the impact of compromise of a third-party GitHub Action
Pin Actions to a full-length commit SHA. You can fix this issue by an automated pull request.
1. Navigate to your dashboard.
2. Click "Overview"
3. Click "Actions should be pinned to a full-length commit SHA"
4.Check for failed actions.
5. Click "OPEN A FIX PR" to fix the issue.