From 39664cb5d9c1fc76045c66f99bfb4c5750f0520c Mon Sep 17 00:00:00 2001 From: jon8787 <112368577+jon8787@users.noreply.github.com> Date: Tue, 14 Apr 2026 14:19:45 +1000 Subject: [PATCH] UID2-6913: Pin third-party GitHub Action refs to commit SHAs Co-Authored-By: Claude Opus 4.6 --- .github/workflows/docker-image.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/docker-image.yml b/.github/workflows/docker-image.yml index e59a871e..5d7a5d24 100644 --- a/.github/workflows/docker-image.yml +++ b/.github/workflows/docker-image.yml @@ -33,7 +33,7 @@ jobs: type=sha,prefix=server_only-,format=short type=raw,prefix=server_only-,value=latest - name: Build and push Docker server_only image - uses: docker/build-push-action@v5 + uses: docker/build-push-action@ca052bb54ab0790a636c9b5f226502c73d547a25 # v5 with: context: publisher/server_only push: true @@ -62,7 +62,7 @@ jobs: type=sha,prefix=standard-,format=short type=raw,prefix=standard-,value=latest - name: Build and push Docker standard image - uses: docker/build-push-action@v5 + uses: docker/build-push-action@ca052bb54ab0790a636c9b5f226502c73d547a25 # v5 with: context: publisher/standard push: true @@ -91,7 +91,7 @@ jobs: type=sha,prefix=reverse-proxy-,format=short type=raw,prefix=reverse-proxy-,value=latest - name: Build and push Docker reverse-proxy image - uses: docker/build-push-action@v5 + uses: docker/build-push-action@ca052bb54ab0790a636c9b5f226502c73d547a25 # v5 with: context: tools/reverse-proxy file: Dockerfile