Pin versions of "untrusted" 3rd-party GitHub Actions (#11319)
According to https://docs.github.com/en/free-pro-team@latest/actions/learn-github-actions/security-hardening-for-github-actions#using-third-party-actionsa it's best practice not to use tags in case of untrusted 3rd-party actions in order to avoid potential attacks.
J
Jarek Potiuk committed
fe59f2622337616fe1902bb6d7e1bce6f002ffa8
Parent: d86cf37
Committed by GitHub <noreply@github.com>
on 10/7/2020, 11:23:41 AM