Skip to content

Conversation

@adanalvarez
Copy link

This PR updates the action reference from a version tag (@v1) to a specific commit SHA (@698a1d4) for the action LoveToKnow/slackify-markdown-action.

This change follows security best practices recommended by GitHub: Security hardening for GitHub Actions

By explicitly pinning the action to a commit SHA, we avoid creating an "unpinnable dependency" for users consuming this action, as described here: Risks of unpinnable GitHub actions

@Tello-Wharton
Copy link
Contributor

Resolved by #221

@Tello-Wharton
Copy link
Contributor

Huh, just realised we opened the same PR - sorry 😂

@mrrobot47
Copy link
Member

mrrobot47 commented Apr 9, 2025

I merged the newer one, my bad 😅 #221

@mrrobot47 mrrobot47 closed this Apr 9, 2025
@mrrobot47 mrrobot47 reopened this Apr 9, 2025
@mrrobot47 mrrobot47 merged commit 48bcc47 into rtCamp:master Apr 9, 2025
1 check passed
@mrrobot47
Copy link
Member

mrrobot47 commented Apr 9, 2025

Thanks for the contribution 🙏
Merged PR and added as contributor to the action: https://github.com/rtCamp/action-slack-notify/releases/tag/v2.3.3

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants