Pin GitHub Action tags to full commit SHAs and generate auditable lockfiles to prevent supply chain attacks
-
Updated
Mar 22, 2026 - TypeScript
Pin GitHub Action tags to full commit SHAs and generate auditable lockfiles to prevent supply chain attacks
ActVer plugin & skills for AI coding agents such as Claude Code, Cursor, and Copilot — GitHub Actions version lookup, SHA pinning, and workflow security auditing
Add a description, image, and links to the sha-pinning topic page so that developers can more easily learn about it.
To associate your repository with the sha-pinning topic, visit your repo's landing page and select "manage topics."