You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@commons.apache.org by "step-security-bot (via GitHub)" <gi...@apache.org> on 2023/06/24 21:00:44 UTC
[GitHub] [commons-jexl] step-security-bot opened a new pull request, #180: [StepSecurity] ci: Harden GitHub Actions
step-security-bot opened a new pull request, #180:
URL: https://github.com/apache/commons-jexl/pull/180
## Summary
This pull request is created by [Secure Repo](https://app.stepsecurity.io/securerepo) at the request of @garydgregory. Please merge the Pull Request to incorporate the requested changes. Please tag @garydgregory on your message if you have any questions related to the PR. You can also engage with the [StepSecurity](https://github.com/step-security) team by tagging @step-security-bot.
## Security Fixes
### Pinned Dependencies
GitHub Action tags and Docker tags are mutatble. This poses a security risk. GitHub's Security Hardening guide recommends pinning actions to full length commit.
- [GitHub Security Guide](https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-third-party-actions)
- [The Open Source Security Foundation (OpenSSF) Security Guide](https://github.com/ossf/scorecard/blob/main/docs/checks.md#pinned-dependencies)
## Feedback
For bug reports, feature requests, and general feedback; please create an issue in [step-security/secure-repo](https://github.com/step-security/secure-repo). To create such PRs, please visit https://app.stepsecurity.io/securerepo.
Signed-off-by: StepSecurity Bot <bo...@stepsecurity.io>
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: issues-unsubscribe@commons.apache.org
For queries about this service, please contact Infrastructure at:
users@infra.apache.org
[GitHub] [commons-jexl] garydgregory merged pull request #180: [StepSecurity] ci: Harden GitHub Actions
Posted by "garydgregory (via GitHub)" <gi...@apache.org>.
garydgregory merged PR #180:
URL: https://github.com/apache/commons-jexl/pull/180
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: issues-unsubscribe@commons.apache.org
For queries about this service, please contact Infrastructure at:
users@infra.apache.org