Pin your GitHub Actions. Prick holes in their supply chain security.
-
Updated
Jun 10, 2026 - Rust
Pin your GitHub Actions. Prick holes in their supply chain security.
ActVer plugin & skills for AI coding agents such as Claude Code, Cursor, and Copilot — GitHub Actions version lookup, SHA pinning, and workflow security auditing
Pin GitHub Action tags to full commit SHAs and generate auditable lockfiles to prevent supply chain attacks
secure-by-default github template for oss: signed commits, sha-pinned actions, slsa v1.0 provenance, sigstore keyless signing, npm oidc publishing.
Add a description, image, and links to the sha-pinning topic page so that developers can more easily learn about it.
To associate your repository with the sha-pinning topic, visit your repo's landing page and select "manage topics."