Skip to content

supply chain improvement on dockerfile #425

@venkatamutyala

Description

@venkatamutyala

Suggestion

i believe with the current approach everyone gets the latest version of the docker image even if they are pinned on a specific version of your GitHub action. i think pinning to a sha would help reduce a supply chain attack

FROM danielflook/terraform-github-actions-base:latest

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions