Pin your GitHub Actions. Prick holes in their supply chain security.
-
Updated
May 26, 2026 - Rust
Pin your GitHub Actions. Prick holes in their supply chain security.
Pin GitHub Action tags to full commit SHAs and generate auditable lockfiles to prevent supply chain attacks
ActVer plugin & skills for AI coding agents such as Claude Code, Cursor, and Copilot — GitHub Actions version lookup, SHA pinning, and workflow security auditing
secure-by-default github template for oss: signed commits, sha-pinned actions, slsa v1.0 provenance, sigstore keyless signing, npm oidc publishing.
Add a description, image, and links to the sha-pinning topic page so that developers can more easily learn about it.
To associate your repository with the sha-pinning topic, visit your repo's landing page and select "manage topics."