security: pin GitHub Actions to reviewed SHAs - #11
Conversation
There was a problem hiding this comment.
Sorry @mkarson1997, you've used your own review budget of 250,000 diff characters for the last 7 days.
You can request another review in 1 day and 23 hours by commenting @sourcery-ai review. Upgrade to get a review now.
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Reviewer's guide (collapsed on small PRs)Reviewer's GuideReplaces mutable GitHub Actions tags with reviewed immutable commit SHAs across CI and CodeQL workflows, upgrades CodeQL actions to v4, and preserves the existing .NET 8 build and C# security-analysis configuration. File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
What changed
Why
KARZOUN ERP is a flagship .NET desktop project. Its validation and security-analysis supply chain should not depend on mutable GitHub Action tags.
Merge only after the Windows build, CodeQL and SonarQube Cloud checks are green.
Summary by Sourcery
Harden GitHub Actions supply-chain integrity by replacing mutable workflow tags with reviewed immutable commits.
Enhancements:
CI: