Uh oh!
There was an error while loading. Please reload this page.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔍 Verify the pinned SHA actually corresponds to v7.0.0
The commit SHA is the only thing enforced at run time; the
# v7.0.0comment is unverifiable from the repo. Worth confirming9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0is the tagged v7.0.0 commit of actions/checkout, since a mismatched pin in the security-gate workflow would silently run a different action revision. The subsequent steps (download/extract gitleaks,gitleaks detect --no-git, ripgrep policy script) need no Git credentials, sopersist-credentials: falseis safe here.Was this helpful? React with 👍 or 👎 to provide feedback.