Skip to content

Conversation

@udayshanmugam
Copy link

Summary

This PR addresses unpinned GitHub Actions findings identified by zizmor security tool.

Changes

Updated golangci/golangci-lint-action to latest stable release commit SHA (more than 7 days old):

  • v9.0.0 (0a35821d5c230e903fcfe077583637dea1b27b47)
  • Previous version: v3.7.1 (3cfe3a4abbb849e10058ce4af15d205b6da42804)

Note: v9.1.0 is available but is less than 7 days old, so using v9.0.0 per security best practices.

Files Modified

  • .github/workflows/run-tests.yaml

Verification

Commit SHA verified against GitHub API and corresponds to release v9.0.0 (published 2025-11-07).

Ticket: IS-416

Pin unpinned GitHub Actions to their latest release commit SHAs for security:
- golangci/golangci-lint-action: v9.0.0 (0a35821d5c230e903fcfe077583637dea1b27b47)

Ticket: IS-416
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants