Description
When a GitHub Actions workflow references an external action only by a tag or branch, that name can be moved to a different commit. The same workflow configuration can therefore run unreviewed action code at a later time.
A full-length commit SHA fixes the code referenced in the action repository. It does not make other dependencies downloaded during execution or the workflow’s permissions safe.
Potential impact
- Changes to an external action repository can cause unreviewed code to run in CI.
- Retargeted tags or malicious changes can expose the workflow to supply-chain attacks.
- Results can change over time, reducing reproducibility and auditability.
Remediation
Pin external action uses: references to verified full-length commit SHAs. Confirm that the SHA belongs to the reviewed version in the original repository, and replace it explicitly after validating an update. Review workflow permissions and the action’s other dependencies separately.
Examples
These excerpts compare reference formats using a historical action version. For actual use, review a supported version and separately configure required message inputs, token permissions and other settings.
Before
name: ci
on:
pull_request:
jobs:
comment:
runs-on: ubuntu-latest
steps:
- name: Add comment
uses: thollander/actions-comment-pull-request@v2
After
name: ci
on:
pull_request:
jobs:
comment:
runs-on: ubuntu-latest
steps:
- name: Add comment
uses: thollander/actions-comment-pull-request@b07c7f86be67002023e6cb13f57df3f21cdd3411
The after-example references a specific commit instead of a tag. Review the safety of that commit; SHA pinning does not automatically apply later security updates.