Fedora Account System
Red Hat Associate
Red Hat Customer
## GitHub Actions and reusable workflow not pinned to commit SHA **Component:** operator-foundry GitHub Actions and the reusable dispatch workflow are referenced by mutable tag (e.g. `@v0`, `@v4`) rather than a full commit SHA, allowing an upstream compromise or tag re-point to silently change the code executed in CI. ### Remediation Pin every `uses:` reference to a full 40-character commit SHA with a trailing `# vX.Y.Z` comment (e.g. `actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1`). Enable Dependabot or Renovate `github-actions` ecosystem updates to keep SHA pins current. --- *Source: Ex-Wing/Glasswing Konflux CI security assessment (Mythos), finding FIND-002*