From 3e46e676d33bc67b67f187fa032ee255d90bd545 Mon Sep 17 00:00:00 2001 From: BRADSEC <7948876+bradsec@users.noreply.github.com> Date: Sat, 27 Jun 2026 16:52:35 +1000 Subject: [PATCH] Pin publish action to working v1 commit (supply-chain hardening) Pin Comfy-Org/publish-node-action to commit 0eb6cd742945443bee7f79eeddd4f732780029a1 (the v1 head) so a moved tag cannot inject code. NOTE: the 1.0.1 release tag is broken (runs the removed 'comfy --yes' flag); this commit uses 'comfy --skip-prompt' and works. --- .github/workflows/publish.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 665bf07..62232a6 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -20,7 +20,7 @@ jobs: - name: Check out code uses: actions/checkout@v4 - name: Publish Custom Node - uses: Comfy-Org/publish-node-action@v1 + uses: Comfy-Org/publish-node-action@0eb6cd742945443bee7f79eeddd4f732780029a1 # v1 (1.0.1 tag broken: removed comfy --yes flag) with: ## Add your own personal access token to your Github Repository secrets and reference it here. personal_access_token: ${{ secrets.REGISTRY_ACCESS_TOKEN }}