| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Using tags is a security risk, as they can be updated to point to anything else. Refs: nodejs/corepack#117 (comment)
|
Review requested:
|
Sorry, something went wrong.
Isn't this also valid for actions/* actions? |
Sorry, something went wrong.
actions/* are controlled by GitHub, who controls the runners and the secrets anyway, so I don't think it's a risk to trust them with tags. |
Sorry, something went wrong.
Co-authored-by: Michaël Zasso <targos@protonmail.com>
|
glad that we're doing this :) |
Sorry, something went wrong.
Commit Queue failed- Loading data for nodejs/node/pull/43284 ✔ Done loading data for nodejs/node/pull/43284 ----------------------------------- PR info ------------------------------------ Title tools: use hashes instead of tags for external actions (#43284) ⚠ Could not retrieve the email or name of the PR author's from user's GitHub profile! Branch aduh95:no-tags-for-external-actions -> nodejs:master Labels meta, author ready, commit-queue-squash Commits 2 - tools: use hashes instead of tags for external actions - Apply suggestions from code review Committers 2 - Antoine du Hamel - GitHub PR-URL: https://github.com/nodejs/node/pull/43284 Reviewed-By: Michaël Zasso Reviewed-By: Luigi Pinca ------------------------------ Generated metadata ------------------------------ PR-URL: https://github.com/nodejs/node/pull/43284 Reviewed-By: Michaël Zasso Reviewed-By: Luigi Pinca -------------------------------------------------------------------------------- ℹ This PR was created on Wed, 01 Jun 2022 15:21:17 GMT ✔ Approvals: 2 ✔ - Michaël Zasso (@targos) (TSC): https://github.com/nodejs/node/pull/43284#pullrequestreview-993164651 ✔ - Luigi Pinca (@lpinca): https://github.com/nodejs/node/pull/43284#pullrequestreview-995322504 ✖ Last GitHub CI failed ℹ Green GitHub CI is sufficient -------------------------------------------------------------------------------- ✔ Aborted `git node land` session in /home/runner/work/node/node/.ncuhttps://github.com/nodejs/node/actions/runs/2444122549 |
Sorry, something went wrong.
Using tags is a security risk, as they can be updated to point to anything else. Refs: nodejs/corepack#117 (comment) PR-URL: #43284 Reviewed-By: Michaël Zasso <targos@protonmail.com> Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
Using tags is a security risk, as they can be updated to point to anything else. Refs: nodejs/corepack#117 (comment) PR-URL: #43284 Reviewed-By: Michaël Zasso <targos@protonmail.com> Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
Using tags is a security risk, as they can be updated to point to anything else. Refs: nodejs/corepack#117 (comment) PR-URL: #43284 Reviewed-By: Michaël Zasso <targos@protonmail.com> Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
Using tags is a security risk, as they can be updated to point to anything else. Refs: nodejs/corepack#117 (comment) PR-URL: #43284 Reviewed-By: Michaël Zasso <targos@protonmail.com> Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
Using tags is a security risk, as they can be updated to point to anything else. Refs: nodejs/corepack#117 (comment) PR-URL: nodejs/node#43284 Reviewed-By: Michaël Zasso <targos@protonmail.com> Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
| Back | FazBrowse Home | New Git URL |
Using tags is a security risk, as they can be updated to point to
anything else.
Refs: nodejs/corepack#117 (comment)