Skip to content

fix: pin release-please-action to commit SHA#11

Merged
rjamul-elnora-ai merged 1 commit intomainfrom
fix/codeql-unpinned-action-tag
Mar 23, 2026
Merged

fix: pin release-please-action to commit SHA#11
rjamul-elnora-ai merged 1 commit intomainfrom
fix/codeql-unpinned-action-tag

Conversation

@rjamul-elnora-ai
Copy link
Copy Markdown
Member

Summary

Pin googleapis/release-please-action from mutable @v4 tag to exact commit SHA (16a9c90856f42705d54a6fda1823352bdc62cf38). Resolves CodeQL alert #1 (actions/unpinned-tag, medium severity).

Zero functional change — same version, same behavior. Protects against supply chain tag mutation attacks.

Test plan

🤖 Generated with Claude Code

Pin googleapis/release-please-action to exact commit hash instead of
mutable v4 tag. Resolves CodeQL alert #1 (actions/unpinned-tag).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@rjamul-elnora-ai rjamul-elnora-ai merged commit 0ccfcac into main Mar 23, 2026
3 checks passed
@rjamul-elnora-ai rjamul-elnora-ai deleted the fix/codeql-unpinned-action-tag branch March 23, 2026 22:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants