Pin third-party actions to full commit SHAs (#39)

Replace mutable v1 tag references with immutable commit SHAs so a
compromised or force-moved tag cannot inject code into reusable
workflows. Each pin keeps a # v1 comment for readability.

- claude-code-action in compliance-audit.yaml
- ruby/setup-ruby in cd-mobile-ios.yaml (v1 branch)
This commit is contained in:
Adam Moussa 2026-06-05 12:13:12 -04:00 • committed by GitHub
parent 62d82eae29
commit 2e74e2a670
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 2 additions and 2 deletions

View file

@ -73,7 +73,7 @@ jobs:
cache: npm
cache-dependency-path: ${{ inputs.cache-dependency-path }}
- uses: ruby/setup-ruby@v1
- uses: ruby/setup-ruby@afeafc3d1ab54a631816aba4c914a0081c12ff2f # v1
with:
ruby-version: ${{ inputs.ruby-version }}
bundler-cache: true

View file

@ -71,7 +71,7 @@ jobs:
- name: Run compliance audit
id: audit
uses: anthropics/claude-code-action@v1
uses: anthropics/claude-code-action@41ea7642c1436fa0ee57aae58347904b71a5af27 # v1
with:
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
prompt: |