From 088425a3d9c76b824cf03ec0bc2e456400977637 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Fri, 5 Jun 2026 11:41:30 -0400 Subject: [PATCH] Pin third-party actions to full commit SHAs Replace mutable v1 tag references with immutable commit SHAs so a compromised or force-moved tag cannot inject code into reusable workflows. Each pin keeps a # v1 comment for readability. - claude-code-action in compliance-audit.yaml - ruby/setup-ruby in cd-mobile-ios.yaml (v1 branch) --- .github/workflows/cd-mobile-ios.yaml | 2 +- .github/workflows/compliance-audit.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/cd-mobile-ios.yaml b/.github/workflows/cd-mobile-ios.yaml index 40036b7..82344e7 100644 --- a/.github/workflows/cd-mobile-ios.yaml +++ b/.github/workflows/cd-mobile-ios.yaml @@ -73,7 +73,7 @@ jobs: cache: npm cache-dependency-path: ${{ inputs.cache-dependency-path }} - - uses: ruby/setup-ruby@v1 + - uses: ruby/setup-ruby@afeafc3d1ab54a631816aba4c914a0081c12ff2f # v1 with: ruby-version: ${{ inputs.ruby-version }} bundler-cache: true diff --git a/.github/workflows/compliance-audit.yaml b/.github/workflows/compliance-audit.yaml index dff1e85..e333dfe 100644 --- a/.github/workflows/compliance-audit.yaml +++ b/.github/workflows/compliance-audit.yaml @@ -71,7 +71,7 @@ jobs: - name: Run compliance audit id: audit - uses: anthropics/claude-code-action@v1 + uses: anthropics/claude-code-action@41ea7642c1436fa0ee57aae58347904b71a5af27 # v1 with: anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }} prompt: |