Skip to content

[Wave 9] Add supply-chain checks for contract CI dependencies and actions #197

Description

@truthixify

Problem

Contract CI mixes floating action versions and tool installers without a consistent provenance or update policy.

Done when

  • Pin third-party actions and compiler tools to reviewed versions or digests.
  • Add dependency review for npm, Cargo, and container inputs.
  • Record the toolchain versions used for release artifacts.
  • Document the update and re-audit process.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Stellar WaveIssues in the Stellar wave program

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions