2025å¹´8æ15æ¥ã« GitHub Actions ã§ãç¹å®ã®ã¢ã¯ã·ã§ã³ããã¼ã¸ã§ã³ããããã¯ããæ©è½ãã¨ãã¢ã¯ã·ã§ã³ã® SHA åºå®ãå¼·å¶ããæ©è½ãããªãªã¼ã¹ãããð¡ github.blog ãã¨ãã° GitHub Actions ã§ä½¿ã£ã¦ããã¢ã¯ã·ã§ã³ã«ããã¯ãã¢çãªèå¼±æ§ãçµã¿è¾¼ã¾ãã¦ãã¾ã£ãå ´åã®ãªã¹ã¯ãæå¶ã§ããï¼ä»å¹´ã 㨠tj-actions/changed-files ã®ä»¶ããã£ããããï¼ nvd.nist.gov å人çã«ãã¢ã¯ã·ã§ã³ã® SHA åºå®ãå¼·å¶ããæ©è½ (Enforce SHA pinning)ãã«èå³ããã£ã¦ãã£ãã試ãã¦ã¿ãâï¸ä»åã¯ãµã³ãã«ã¨ã㦠actions/checkout ã使ãï¼ github.com ð¾ .github/workflows/deploy.ymlï¼ãã¼ã¸ã§ã³åºå®ï¼ ã¾ã㯠Enforce SHA pinning ãæå¹åãã


{{#tags}}- {{label}}
{{/tags}}