.github/.github/workflows
Adam Moussa 2e74e2a670
Pin third-party actions to full commit SHAs (#39)
Replace mutable v1 tag references with immutable commit SHAs so a
compromised or force-moved tag cannot inject code into reusable
workflows. Each pin keeps a # v1 comment for readability.

- claude-code-action in compliance-audit.yaml
- ruby/setup-ruby in cd-mobile-ios.yaml (v1 branch)
2026-06-05 12:13:12 -04:00
..
callable-dependency-review.yaml Add dependency-review workflow and Sea Haven PR checklist (#36) 2026-06-05 12:11:36 -04:00
cd-cdk.yaml chore(ci): bump configure-aws-credentials to v6 (#35) 2026-06-05 12:12:30 -04:00
cd-mobile-ios.yaml Pin third-party actions to full commit SHAs (#39) 2026-06-05 12:13:12 -04:00
cd-sam.yaml chore(ci): bump configure-aws-credentials to v6 (#35) 2026-06-05 12:12:30 -04:00
ci-dotnet.yaml Add cancel-in-progress concurrency to reusable CI (#38) 2026-06-05 12:12:55 -04:00
ci-python-sam.yaml Add cancel-in-progress concurrency to reusable CI (#38) 2026-06-05 12:12:55 -04:00
ci-typescript-cdk.yaml Add cancel-in-progress concurrency to reusable CI (#38) 2026-06-05 12:12:55 -04:00
compliance-audit.yaml Pin third-party actions to full commit SHAs (#39) 2026-06-05 12:13:12 -04:00
dependabot-auto-merge.yaml Add Dependabot auto-merge workflow (#6) 2026-05-07 18:45:22 -04:00