From 4e551e432f1b7e7ebdabd3e35b27c7a177569c5f Mon Sep 17 00:00:00 2001 From: Christine Chen <10511452+christineschen@users.noreply.github.com> Date: Tue, 23 Jun 2026 18:14:27 -0400 Subject: [PATCH] fix: pin create-github-app-token to immutable SHA Pin actions/create-github-app-token to v3.2.0 commit SHA (bcd2ba49...) instead of mutable @v3 tag to prevent supply chain attacks where a compromised account could force-push malicious code to the tag. This eliminates the risk of secret leakage and malicious code execution in CI workflows. --- .github/workflows/auto-merge-speakeasy-pr.yaml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.github/workflows/auto-merge-speakeasy-pr.yaml b/.github/workflows/auto-merge-speakeasy-pr.yaml index 29e7603..e0035f8 100644 --- a/.github/workflows/auto-merge-speakeasy-pr.yaml +++ b/.github/workflows/auto-merge-speakeasy-pr.yaml @@ -33,7 +33,8 @@ jobs: steps: - name: Generate GitHub App token id: app-token - uses: actions/create-github-app-token@v3 + # actions/create-github-app-token@v3.2.0 (immutable SHA) + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 with: app-id: ${{ secrets.GH_DOCS_SYNC_APP_ID }} private-key: ${{ secrets.GH_DOCS_SYNC_APP_PRIVATE_KEY }}