Skip to content

ci: pin third-party GitHub Actions to commit SHAs#266

Open
decentraland-bot wants to merge 1 commit into
mainfrom
security/pin-github-actions-sha
Open

ci: pin third-party GitHub Actions to commit SHAs#266
decentraland-bot wants to merge 1 commit into
mainfrom
security/pin-github-actions-sha

Conversation

@decentraland-bot
Copy link
Copy Markdown
Contributor

Summary

Pin mutable branch references (@master) on third-party GitHub Actions to immutable commit SHAs, preventing supply chain attacks if a third-party maintainer account is compromised.

Actions pinned (varies by repo):

  • menduz/oddish-action@master@b08e3123
  • arduino/setup-protoc@master@3ea1d70a
  • dtolnay/rust-toolchain@master@3c5f7ea2
  • ammaraskar/gcc-problem-matcher@master@cb2e3f94
  • ammaraskar/msvc-problem-matcher@master@541aa436

The SHA comment preserves the original human-readable reference.

Requested by Ignacio Mazzara via Slack

@decentraland-bot decentraland-bot requested a review from a team as a code owner May 18, 2026 14:01
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented May 18, 2026

badge

Windows and Mac build successful in Launcher Rust!! You can find a link to the downloadable artifact below.

Name Link
Commit a6c2163
Download Plain Windows S3 dcl_launcher.exe
Download Windows S3 Decentraland_installer.exe
Download Mac S3 Decentraland_installer.dmg
Built on 2026-05-18T14:17:24Z

@cyaiox cyaiox requested review from NickKhalow and aixaCode May 18, 2026 18:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant