Skip to content

Conversation

@jalseth
Copy link
Member

@jalseth jalseth commented Nov 9, 2025

This improves security by not trusting Git tags which can be updated behind the scenes to inject malicious code without any changes to conftest or its workflows.

@jalseth jalseth force-pushed the jalseth/ci-use-ratchet branch from 41a4e78 to cd172f9 Compare November 9, 2025 03:19
This improves security by not trusting Git tags which can be updated behind the scenes
to inject malicious code without any changes to conftest or its workflows.

Signed-off-by: James Alseth <[email protected]>
@jalseth jalseth force-pushed the jalseth/ci-use-ratchet branch from cd172f9 to d5b7007 Compare November 9, 2025 03:23
@jalseth jalseth marked this pull request as ready for review November 9, 2025 03:25
@jalseth jalseth requested review from boranx and jpreese November 9, 2025 03:25
@jalseth jalseth added the github_actions Pull requests that update GitHub Actions code label Nov 9, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants