Skip to content

VLN-1359: remediate unpinned-github-actions#373

Open
picatz wants to merge 2 commits into
mainfrom
camper/unpinned-github-actions-finding-pin-actions-worker-controller
Open

VLN-1359: remediate unpinned-github-actions#373
picatz wants to merge 2 commits into
mainfrom
camper/unpinned-github-actions-finding-pin-actions-worker-controller

Conversation

@picatz

@picatz picatz commented Jun 11, 2026

Copy link
Copy Markdown
Contributor

🏕️ This pull request was created by camper, an automated security campaign tool.

Finding

Ruleunpinned-github-actions
SeverityMEDIUM
Repositorytemporalio/temporal-worker-controller
TicketVLN-1359

Summary

🤠 Deputy pinned dependencies to immutable references.

  • Total refs: 31
  • Pinned refs: 22
  • Already pinned: 9

Changed references:

  • actions/checkout: v6 -> df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
  • azure/setup-helm: v4 -> 1a275c3b69536ee54be43f2070a358922e12c8d4 # v4.3.1
  • imjasonh/setup-crane: v0.4 -> 31b88efe9de28ae0ffa220711af4b60be9435f6e # v0.4
  • actions/setup-go: v5 -> 40f1582b2485089dde7abd97c1529aa768e1baff # v5.6.0
  • actions/checkout: v6 -> df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
  • azure/setup-helm: v3 -> 5119fcb9089d432beecbf79bb2c7915207344b78 # v3.5
  • actions/checkout: v6 -> df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
  • azure/setup-helm: v3 -> 5119fcb9089d432beecbf79bb2c7915207344b78 # v3.5
  • actions/create-github-app-token: v3.1.1 -> 1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1
  • actions/checkout: v6 -> df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
  • +12 more

Instructions

  • Approve to merge this fix
  • Request changes to trigger a new remediation attempt
  • /camper rebase — rebase onto the base branch
  • /camper close — close this PR without merging
  • /camper retry — close and retry with a new fix

@picatz picatz requested review from a team and jlegrone as code owners June 11, 2026 17:34

@jaypipes jaypipes left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍 I've been meaning to get around to pinning to immutable GH action releases. thank you @picatz :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants