Skip to content

govulncheck-action: pin action dependencies by sha #75908

@lufia

Description

@lufia

Hi team.

We use govulncheck-action for our internal repositories to report vulnerability.

In this August, GitHub published Require actions to be pinned to a full-length commit SHA option, and then our company decided on a policy to enable that option gradually last week.
https://github.blog/changelog/2025-08-15-github-actions-policy-now-supports-blocking-and-sha-pinning-actions/

There are some tag references in govulncheck-action/action.yml. Is there a plan to migrate them to hash?

Metadata

Metadata

Assignees

No one assigned

    Labels

    FeatureRequestIssues asking for a new feature that does not need a proposal.NeedsInvestigationSomeone must examine and confirm this is a valid issue and not a duplicate of an existing one.

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions