Pin third-party actions to full commit SHAs

Replace mutable v1 tag references with immutable commit SHAs so a
compromised or force-moved tag cannot inject code into reusable
workflows. Each pin keeps a # v1 comment for readability.

- claude-code-action in compliance-audit.yaml
- ruby/setup-ruby in cd-mobile-ios.yaml (v1 branch)
This commit is contained in:
Adam Moussa 2026-06-05 11:41:30 -04:00
parent 204958e8d9
commit 088425a3d9
2 changed files with 2 additions and 2 deletions

View file

@ -73,7 +73,7 @@ jobs:
cache: npm
cache-dependency-path: ${{ inputs.cache-dependency-path }}
- uses: ruby/setup-ruby@v1
- uses: ruby/setup-ruby@afeafc3d1ab54a631816aba4c914a0081c12ff2f # v1
with:
ruby-version: ${{ inputs.ruby-version }}
bundler-cache: true

View file

@ -71,7 +71,7 @@ jobs:
- name: Run compliance audit
id: audit
uses: anthropics/claude-code-action@v1
uses: anthropics/claude-code-action@41ea7642c1436fa0ee57aae58347904b71a5af27 # v1
with:
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
prompt: |