Skip to content

GitHub Actions: Pin actions to SHA hashes [NIT-2436]#192

Merged
bshand merged 2 commits intodevelopfrom
feature/NIT-2436/pin_github_actions
Apr 22, 2026
Merged

GitHub Actions: Pin actions to SHA hashes [NIT-2436]#192
bshand merged 2 commits intodevelopfrom
feature/NIT-2436/pin_github_actions

Conversation

@bshand
Copy link
Copy Markdown
Contributor

@bshand bshand commented Apr 13, 2026

https://nhsd-jira.digital.nhs.uk/browse/NIT-2436

Ensure that all active GitHub actions on the data_management_system repository are pinned to SHA hashes.
Add dependabot checks for GitHub Actions.
This is to reduce the risk of supply chain attacks, cf. https://docs.github.com/en/actions/reference/security/secure-use#using-third-party-actions

The integration test failures are known brittle tests, unrelated to this commit.

@bshand bshand changed the title GitHub Actions: Pin actions to SHA hashes GitHub Actions: Pin actions to SHA hashes [NIT-2436] Apr 14, 2026
@bshand bshand merged commit 9a38886 into develop Apr 22, 2026
12 of 19 checks passed
@bshand bshand deleted the feature/NIT-2436/pin_github_actions branch April 22, 2026 19:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant