Skip to content

SEC-090: Automated trusted workflow pinning (2023-04-03)#28

Merged
dlaguerta merged 2 commits intomainfrom
tsccr-auto-pinning/trusted/2023-04-03
Apr 13, 2023
Merged

SEC-090: Automated trusted workflow pinning (2023-04-03)#28
dlaguerta merged 2 commits intomainfrom
tsccr-auto-pinning/trusted/2023-04-03

Conversation

@hashicorp-tsccr
Copy link
Copy Markdown
Contributor

Hello,
This PR was auto-generated to pin the Actions workflow files in this repository to use trusted SHAs.
This is in support of RFC SEC-090 which is due to be implemented by EOQ2 FY24.

Please do the following:

  • Approve and merge this PR if you are happy with the changes.
  • Check if there are any untrusted third-party Actions in the workflow files and onboard them to the TSCCR.
  • The yaml comment "# TSCCR: no entry for repository " in the workflow files identifies an untrusted Action.
  • If you have to onboard any third-party Actions, update and pin your workflows using the tsccr-helper tool after the Actions have been onboarded OR reach out to #team-prodsec and we can run this automation again.
  • Verify that your Actions are still working as expected after pinning.

Please reach out to #team-prodsec if you have any questions.

@hashicorp-tsccr hashicorp-tsccr bot requested a review from a team April 3, 2023 15:51
@hashicorp-tsccr hashicorp-tsccr bot added SEC-090 Relating to RFC SEC-090. SEC-090/Pinning/Trusted Automated TSCCR pinning PR to trusted SHAs. labels Apr 3, 2023
@hashicorp-cla
Copy link
Copy Markdown

hashicorp-cla commented Apr 3, 2023

CLA assistant check
All committers have signed the CLA.

@dlaguerta dlaguerta merged commit 63c7593 into main Apr 13, 2023
@dlaguerta dlaguerta deleted the tsccr-auto-pinning/trusted/2023-04-03 branch April 13, 2023 19:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

SEC-090/Pinning/Trusted Automated TSCCR pinning PR to trusted SHAs. SEC-090 Relating to RFC SEC-090.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants