Skip to content

GitHub Actions: Pin actions to SHA hashes#192

Open
bshand wants to merge 2 commits intodevelopfrom
feature/NIT-2436/pin_github_actions
Open

GitHub Actions: Pin actions to SHA hashes#192
bshand wants to merge 2 commits intodevelopfrom
feature/NIT-2436/pin_github_actions

Conversation

@bshand
Copy link
Copy Markdown
Contributor

@bshand bshand commented Apr 13, 2026

https://nhsd-jira.digital.nhs.uk/browse/NIT-2436

Ensure that all active GitHub actions on the data_management_system repository are pinned to SHA hashes.
Add dependabot checks for GitHub Actions.
This is to reduce the risk of supply chain attacks, cf. https://docs.github.com/en/actions/reference/security/secure-use#using-third-party-actions

The integration test failures are known brittle tests, unrelated to this commit.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant