GitHub Actions security scanner: pin actions to SHAs, detect script injection, audit permissions. Fix supply chain vulnerabilities.
-
Updated
Feb 28, 2026 - Python
GitHub Actions security scanner: pin actions to SHAs, detect script injection, audit permissions. Fix supply chain vulnerabilities.
Pin GitHub Action tags to full commit SHAs and generate auditable lockfiles to prevent supply chain attacks
Supply-chain-hardened release tool for JS/TS libraries. Multi-runner reproducible-build attestation, OIDC trusted publishing, hard pre-publish gates. Pure bash, zero dependencies.
Add a description, image, and links to the action-pinning topic page so that developers can more easily learn about it.
To associate your repository with the action-pinning topic, visit your repo's landing page and select "manage topics."