Skip to content

Conversation

tykeal
Copy link
Member

@tykeal tykeal commented Feb 11, 2025

Summary

This pull request is created by StepSecurity at the request of @tykeal. Please merge the Pull Request to incorporate the requested changes. Please tag @tykeal on your message if you have any questions related to the PR.

Security Fixes

Pinned Dependencies

GitHub Action tags and Docker tags are mutable. This poses a security risk. GitHub's Security Hardening guide recommends pinning actions to full length commit.

Feedback

For bug reports, feature requests, and general feedback; please email [email protected]. To create such PRs, please visit https://app.stepsecurity.io/securerepo.

Signed-off-by: StepSecurity Bot [email protected]
Signed-off-by: Andrew Grimberg [email protected]

Signed-off-by: StepSecurity Bot <[email protected]>
Signed-off-by: Andrew Grimberg <[email protected]>
@tykeal tykeal mentioned this pull request Feb 11, 2025
@tykeal tykeal enabled auto-merge February 11, 2025 14:24
@tykeal tykeal merged commit c7873d4 into lfit:main Feb 11, 2025
6 checks passed
@tykeal tykeal deleted the stepsecurity_remediation_1739282877 branch February 11, 2025 14:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants