Pin your GitHub Actions. Prick holes in their supply chain security.
-
Updated
Aug 7, 2026 - Rust
Pin your GitHub Actions. Prick holes in their supply chain security.
Harden and manage your GitHub Actions: SHA-pin every action, enforce allowlist policies, update interactively, and analyze run health
The fleet control plane for GitHub Actions — observe, audit, and fix workflows across your whole org from one self-hosted UI, API, and CLI. Every fix ships as a reviewable pull request.
secure-by-default github template for oss: signed commits, sha-pinned actions, slsa v1.0 provenance, sigstore keyless signing, npm oidc publishing.
ActVer plugin & skills for AI coding agents such as Claude Code, Cursor, and Copilot — GitHub Actions version lookup, SHA pinning, and workflow security auditing
Pin GitHub Action tags to full commit SHAs and generate auditable lockfiles to prevent supply chain attacks
A small GitHub Actions policy lab for evaluating the effects of repository settings on locally defined actions
The GitHub Actions the edgeproc repos share instead of each hand-rolling: 7 reusable workflows + 5 composite actions for gates, secret scanning, dependency audit, OIDC publish to PyPI/npm, and Pages deploy. Every uses: is SHA-pinned; a scheduled job reports the 29 controls consumers still hand-roll.
Audit your GitHub Actions supply chain security with pinprick
Add a description, image, and links to the sha-pinning topic page so that developers can more easily learn about it.
To associate your repository with the sha-pinning topic, visit your repo's landing page and select "manage topics."