Files: All workflow files under .github/workflows/
Examples of unpinned actions: actions/checkout@v5, aws-actions/configure-aws-credentials@v6, google-github-actions/auth@v3, azure/login@v3, hashicorp/setup-terraform@v4, docker/build-push-action@v7, golangci/golangci-lint-action@v9.
Mutable tags can be redirected to malicious commits if the action author's account is compromised. The deploy workflows run with id-token: write and access to all cloud credentials.
aquasecurity/trivy-action@0.30.0 uses a version string (not a major tag) but is still not SHA-pinned.
Fix: Pin all third-party actions to their full commit SHAs. Use pin-github-actions or Dependabot with versioning-strategy: lockfile-only to maintain the pins automatically.
Files: All workflow files under
.github/workflows/Examples of unpinned actions:
actions/checkout@v5,aws-actions/configure-aws-credentials@v6,google-github-actions/auth@v3,azure/login@v3,hashicorp/setup-terraform@v4,docker/build-push-action@v7,golangci/golangci-lint-action@v9.Mutable tags can be redirected to malicious commits if the action author's account is compromised. The deploy workflows run with
id-token: writeand access to all cloud credentials.aquasecurity/trivy-action@0.30.0uses a version string (not a major tag) but is still not SHA-pinned.Fix: Pin all third-party actions to their full commit SHAs. Use
pin-github-actionsor Dependabot withversioning-strategy: lockfile-onlyto maintain the pins automatically.