Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

SEC-090: Automated trusted workflow pinning (2023-07-18) #175

Merged
merged 2 commits into from
Sep 11, 2023

Conversation

hashicorp-tsccr[bot]
Copy link
Contributor

This PR was auto-generated by hashicorp/security-tsccr/actions/runs/5589947269

You can alter the configuration of this automation via the hcl config in hashicorp/security-tsccr/automation

This is in support of RFC SEC-090 which is due to be implemented by EOQ2 FY24.

Please do the following:

  • Approve and merge this PR if you are happy with the changes.
  • Check if there are any untrusted third-party Actions in the workflow files and onboard them to the TSCCR.
  • The yaml comments "# TSCCR: no entry for repository..." or "# TSCCR: no version of..." in the workflow files identifies an untrusted Action.
  • If you have to onboard any third-party Actions, update and pin your workflows using the tsccr-helper tool after the Actions have been onboarded OR reach out to #team-prodsec and we can run this automation again.
  • Verify that your Actions are still working as expected after pinning.

Please reach out to #team-prodsec if you have any questions.

@hashicorp-tsccr hashicorp-tsccr bot requested a review from a team as a code owner July 18, 2023 16:24
@hashicorp-tsccr hashicorp-tsccr bot added the SEC-090 Auto-pinning label Jul 18, 2023
@nywilken nywilken force-pushed the tsccr-auto-pinning/trusted/2023-07-18 branch from 3c07f77 to 9adf089 Compare September 11, 2023 18:50
Copy link
Contributor

@nywilken nywilken left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@nywilken nywilken merged commit 9342d06 into main Sep 11, 2023
@nywilken nywilken deleted the tsccr-auto-pinning/trusted/2023-07-18 branch September 11, 2023 18:51
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
SEC-090 Auto-pinning
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant