Skip to content

Commit 50075e5

Browse files
jkennedyvzPosture Fix
andauthored
ci: SHA-pin third-party Gradle actions (#107)
Pin gradle/actions/setup-gradle and gradle/gradle-build-action to full commit SHAs to prevent supply chain attacks via tag hijacking. - gradle/actions/setup-gradle@v6 → @205054a... (ci.yml ×2, codeql.yml) - gradle/gradle-build-action@v3 → @12318b0... (ci.yml, publish-sonatype.yml) Co-authored-by: Posture Fix <posture-fix@langchain.ai>
1 parent 1183469 commit 50075e5

3 files changed

Lines changed: 5 additions & 5 deletions

File tree

.github/workflows/ci.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@ jobs:
3737
cache: gradle
3838

3939
- name: Set up Gradle
40-
uses: gradle/actions/setup-gradle@v6
40+
uses: gradle/actions/setup-gradle@205054a7257716ec64af10a2e2ff1ac5d3b132db # v6
4141

4242
- name: Run lints
4343
run: ./scripts/lint
@@ -64,7 +64,7 @@ jobs:
6464
cache: gradle
6565

6666
- name: Set up Gradle
67-
uses: gradle/actions/setup-gradle@v6
67+
uses: gradle/actions/setup-gradle@205054a7257716ec64af10a2e2ff1ac5d3b132db # v6
6868

6969
- name: Build SDK
7070
run: ./scripts/build
@@ -106,7 +106,7 @@ jobs:
106106
cache: gradle
107107

108108
- name: Set up Gradle
109-
uses: gradle/gradle-build-action@v3
109+
uses: gradle/gradle-build-action@12318b01111bfa6462c00534ffa998f8b397b979 # v3
110110

111111
- name: Run tests
112112
run: ./scripts/test

.github/workflows/codeql.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ jobs:
3232
8
3333
21
3434
- name: Set up Gradle
35-
uses: gradle/actions/setup-gradle@v6
35+
uses: gradle/actions/setup-gradle@205054a7257716ec64af10a2e2ff1ac5d3b132db # v6
3636

3737
- name: Initialize CodeQL
3838
uses: github/codeql-action/init@v4

.github/workflows/publish-sonatype.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,7 @@ jobs:
2929
cache: gradle
3030

3131
- name: Set up Gradle
32-
uses: gradle/gradle-build-action@v3
32+
uses: gradle/gradle-build-action@12318b01111bfa6462c00534ffa998f8b397b979 # v3
3333

3434
- name: Publish to Sonatype
3535
run: |-

0 commit comments

Comments
 (0)