Skip to content

chore: pin third-party GitHub Actions to commit SHAs#408

Merged
cyaiox merged 2 commits into
mainfrom
security/pin-github-actions-sha
May 18, 2026
Merged

chore: pin third-party GitHub Actions to commit SHAs#408
cyaiox merged 2 commits into
mainfrom
security/pin-github-actions-sha

Conversation

@decentraland-bot
Copy link
Copy Markdown
Contributor

Summary

Pin mutable branch references (@master) on third-party GitHub Actions to immutable commit SHAs, preventing supply chain attacks if a third-party maintainer account is compromised.

Actions pinned:

  • menduz/oddish-action@master@b08e3123

The SHA comment preserves the original human-readable reference.

Requested by Ignacio Mazzara via Slack

@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 18, 2026

Test this pull request

  • The @dcl/protocol package can be tested in scenes by running
    npm install "https://sdk-team-cdn.decentraland.org/@dcl/protocol/branch//dcl-protocol-1.0.0-26044727330.commit-b476e48.tgz"

juanmahidalgo
juanmahidalgo previously approved these changes May 18, 2026
Copy link
Copy Markdown

@juanmahidalgo juanmahidalgo left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@decentraland-bot decentraland-bot changed the title ci: pin third-party GitHub Actions to commit SHAs chore: pin third-party GitHub Actions to commit SHAs May 18, 2026
@cyaiox cyaiox merged commit 5656db9 into main May 18, 2026
3 checks passed
@cyaiox cyaiox deleted the security/pin-github-actions-sha branch May 18, 2026 18:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants