chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) #72

Merged
amoussa1229 merged 1 commit from chore/INFRA-50-sha-pin-reusables into main 2026-07-06 22:27:19 +00:00
amoussa1229 commented 2026-07-06 22:11:45 +00:00 (Migrated from github.com)

Mutable @main on org reusable-workflow caller refs means a single push to .github can alter every consumer's CI/CD; this pins each caller ref to the reviewed commit SHA (fd60e4c) with a # main comment for readability.

Mutable `@main` on org reusable-workflow caller refs means a single push to `.github` can alter every consumer's CI/CD; this pins each caller ref to the reviewed commit SHA (`fd60e4c`) with a `# main` comment for readability.
github-advanced-security[bot] (Migrated from github.com) reviewed 2026-07-06 22:12:25 +00:00
@ -4,3 +4,3 @@
jobs:
review:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@main
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
github-advanced-security[bot] (Migrated from github.com) commented 2026-07-06 22:12:25 +00:00

CodeQL / Workflow does not contain permissions

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {{}}

Show more details

## CodeQL / Workflow does not contain permissions Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {{}} [Show more details](https://github.com/Sea-Haven-Industries/exec-aide/security/code-scanning/8)
This repo is archived. You cannot comment on pull requests.
No description provided.