github / github/accessibility-scanner

GitHub Script action not pinned to a full-length commit SHA

Open
#169 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
369
Forks
40
Avg merge
1d 9h
Merged PRs (30d)
10

Description

The `accessibility-scanner` workflow uses `actions/github-script@v8` without pinning it to a specific commit SHA. This violates security best practices and causes the pipeline to fail when the **Require actions to be pinned to a full-length commit SHA** setting is enabled.

#### **Steps to Reproduce**
1. Enable **Require actions to be pinned to a full-length commit SHA** in the repository settings.
2. Run the `accessibility-scanner` workflow.
3. Observe the failure caused by the unpinned `actions/github-script` action.

#### **Expected Behavior**
The workflow should run successfully with all actions pinned to full-length commit SHAs.

#### **Actual Behavior**
The workflow fails because `actions/github-script@v8` is not pinned to a commit SHA.

https://github.com/github/accessibility-scanner/blob/db51bb5d470a862cc027836ee1583ab9d5ae5b16/action.yml#L137

Contributor guide

Open the contributing guide

Research direction

Start with action.yml at line 137, referenced in the issue, and inspect the accessibility-scanner workflow's actions/github-script usage. Update the action reference to a full-length commit SHA, then verify that the workflow satisfies the repository's pinning requirement and runs successfully.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions
Domain
ci-cd, security
Issue type
Bug
Difficulty
1/5
Estimated time
Under an hour
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.