| ▲ | Raed667 a day ago | ||||||||||||||||
To get something of a lockfile you can use the hash of the version you want to pin your dependencies: > actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 | |||||||||||||||||
| ▲ | cyphar a day ago | parent | next [-] | ||||||||||||||||
TFA mentions this option and then goes on at some length to explain that this doesn't help for transitive dependencies, which is how these attacks usually work. | |||||||||||||||||
| ▲ | barrkel a day ago | parent | prev [-] | ||||||||||||||||
Transitive dependencies? | |||||||||||||||||
| |||||||||||||||||