What if GitHub Actions were local-first and built using Nix (proper locking)?
https://github.com/cachix/cloud.devenv.sh
Hosted code on GitHub no less