|
|
|
|
|
by mmarian
56 days ago
|
|
There are downsides to it though. You...
- lose vulnerability alerts
- increase maintenance overhead
- take on all that for value that will go to 0 once Immutable Releases gets widely adopted I wrote a couple of blog posts on it, and a makeshift way of tackling that https://developerwithacat.com/blog/202604/github-actions-sup... |
|
zizmor (and other tools) correctly recovers vulnerability information for SHA-pinned actions[1].
[1]: https://docs.zizmor.sh/audits/#known-vulnerable-actions