dapr / dapr/setup-dapr

Immutable Releases

Open
#164 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
11
Forks
9
PR merge metrics
No merged PRs in 30d

Description

Hello. I'd like to request that this repo be migrated to use immutable releases. Following the [Trivy supply chain compromise](https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know/). It has been abundantly clear that this should occur on all GitHub actions as a defense-in-depth measure to prevent tampering with GitHub actions if a future supply chain compromise occurs. Can this be done?

Reference: [Preventing changes to your releases](https://docs.github.com/en/code-security/how-tos/secure-your-supply-chain/establish-provenance-and-integrity/preventing-changes-to-your-releases)

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.