BigMoeOnEdge/.github/workflows
Helldez 8c8c8f1840
ci: pin third-party actions to commit SHAs (#160)
nttld/setup-ndk and softprops/action-gh-release ran from mutable major
tags inside the APK job, which holds a contents:write token. Whoever
controls those tags upstream could have pointed them at unreviewed code
with permission to rewrite this repo's release assets.

Both now resolve to a fixed commit, with the human-readable version in a
trailing comment. GitHub-owned actions stay on major tags: pinning them
would cost an SHA bump on every upstream release for a materially
smaller risk.

The signing keystore was never reachable this way. It lives only in
release-apk.yml, which runs no third-party action and triggers only on
events that already require write access.
2026-08-04 12:19:04 +02:00
..
ci.yml ci: pin third-party actions to commit SHAs (#160) 2026-08-04 12:19:04 +02:00
release-apk.yml chore: declare the app a game, pin what CI claims, and list every flag (#148) 2026-08-02 00:44:50 +02:00