Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
CI: Bump and ref actions by commit SHA in windows-ci.yml
Referencing actions by commit SHA in GitHub workflows guarantees you are using an immutable version. Actions referenced by tags and branches are more vulnerable to attacks, such as the tag being moved to a malicious commit or a malicious commit being pushed to the branch. It's important to make sure the SHA's are from the original repositories and not forks. For reference: https://github.com/msys2/setup-msys2/releases/tag/v2.20.1 msys2/setup-msys2@27b3aa7 https://github.com/actions/checkout/releases/tag/v4.1.0 actions/checkout@8ade135 https://github.com/actions/upload-artifact/releases/tag/v3.1.3 actions/upload-artifact@a8a3f3a Signed-off-by: Gabriela Gutierrez <[email protected]>
- Loading branch information