Remix.run Logo
WillDaSilva a day ago

There's a repository setting you can enable to prevent actions from running unless they have their version pinned to a SHA digest. This setting applies transitively, so while you can't force your dependencies to use SHA pinning for their dependencies, you can block any workflow from running if it doesn't.

nextaccountic 8 hours ago | parent [-]

A lockfile would address this issue, with the added benefit that it would work