Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Hash pin ci.yml workflow #506

Closed
wants to merge 1 commit into from
Closed

Conversation

joycebrum
Copy link
Contributor

Signed-off-by: Joyce <joycebrum@google.com>
Copy link
Owner

@eliben eliben left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't understand -- is the concern here that an attacker will hijack the official actions/checkout action?

@eliben eliben closed this May 17, 2023
@eliben eliben reopened this May 17, 2023
@joycebrum
Copy link
Contributor Author

Yeah the attacker can hijack or tag rename any version if the action repo got compromised.

Although the actions are official they are also open source projects and unfortunatelly can be compromised as any other project could.

But it is important to noticed that this is just an extra precaution (since the token permission is already read only, no much harm could be done).

@eliben
Copy link
Owner

eliben commented May 19, 2023

Thanks for the clarification. I think I'll prefer to keep it simple for now

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants