Skip to content

[Aikido] AI Fix for 3rd party Github Actions should be pinned - #15

Open
aikido-autofix[bot] wants to merge 1 commit into
masterfrom
fix/aikido-security-sast-128076454-hcrp
Open

aikido-autofix[bot] wants to merge 1 commit into
masterfrom
fix/aikido-security-sast-128076454-hcrp

Conversation

@aikido-autofix

Copy link
Copy Markdown

This patch mitigates a potential supply chain attack by pinning the version of third-party Github Actions to their commit SHA.

✅ 1 issue fixed by this PR
Issue Severity           Description
Sast#340723148
HIGH
A third-party GitHub Action was imported, and is not pinned via a hash. This leaves your CI/CD at risk for potential supply chain attacks, if the affected GitHub Action is compromised.

High confidence: Aikido has a robust set of benchmarks for similar fixes, and they are proven to be effective.

@aikido-autofix aikido-autofix Bot added the security Label created by Aikido AutoFix label Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security Label created by Aikido AutoFix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants