Pin your GitHub Actions. Prick holes in their supply chain security.
-
Updated
Sep 3, 2026 - Rust
Pin your GitHub Actions. Prick holes in their supply chain security.
Harden and manage your GitHub Actions: SHA-pin every action, enforce allowlist policies, update interactively, and analyze run health
secure-by-default github template for oss: signed commits, sha-pinned actions, slsa v1.0 provenance, sigstore keyless signing, npm oidc publishing.
A small GitHub Actions policy lab for evaluating the effects of repository settings on locally defined actions
The fleet control plane for GitHub Actions — observe, audit, and fix workflows across your whole org from one self-hosted UI, API, and CLI. Every fix ships as a reviewable pull request.
ActVer plugin & skills for AI coding agents such as Claude Code, Cursor, and Copilot — GitHub Actions version lookup, SHA pinning, and workflow security auditing
Review what a pinned GitHub Action SHA bump actually changes before you approve it.
Pin GitHub Action tags to full commit SHAs and generate auditable lockfiles to prevent supply chain attacks
CLI that hardens GitHub Actions workflows: audits uses: refs, pins tags to commit SHAs, and detects repointed tags — the tj-actions attack vector. Single binary, zero trust by default
The GitHub Actions the edgeproc repos share instead of each hand-rolling: 7 reusable workflows + 5 composite actions for gates, secret scanning, dependency audit, OIDC publish to PyPI/npm, and Pages deploy. Every uses: is SHA-pinned; a scheduled job reports the 29 controls consumers still hand-roll.
Audit your GitHub Actions supply chain security with pinprick
To associate your repository with the sha-pinning topic, visit your repo's landing page and select "manage topics."