apache / apache/tooling-docs

security: pin all pre-commit hooks to SHA

Open
#100 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
HTML
Stars
10
Forks
8
Avg merge
14h 9m
Merged PRs (30d)
6

Description

Examples:

https://github.com/apache/airflow/blob/76ffb4693feb30c5e1e9f7e0a5e630d0c59a5d63/.pre-commit-config.yaml#L422

https://github.com/apache/shiro/blob/8e0e4ac7a7af35c8c8ec552b51cf3bd809196622/.pre-commit-config.yaml#L77

refs https://github.com/apache/tooling-trusted-releases/issues/1591

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by locating the repository's pre-commit configuration and compare its hook revisions with the referenced Apache examples. Check each hook entry for an immutable commit SHA, then verify that all configured hooks are pinned and review the linked trusted-releases issue for any project-specific requirements.

Written by the indexing model from the issue text.

Assessment

Tech stack
git
Domain
security, tooling
Issue type
Refactor
Difficulty
3/5
Estimated time
1-2 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
58/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.