| ▲ | mmarian 2 days ago | |||||||
Agreed. Good news is GitHub will address that with Immutable Releases https://github.blog/news-insights/product-news/whats-coming-... You won't even need to use commit SHA as long as the maintainer follows this approach. | ||||||||
| ▲ | phist_mcgee 2 days ago | parent | next [-] | |||||||
What an absolute joke that it has taken GitHub this long to clean up it's act when it comes to supply chain security. | ||||||||
| ▲ | cyberclimb 13 hours ago | parent | prev [-] | |||||||
The actions/checkout repo still doesn't even use immutable releases so I'll believe it when I see it | ||||||||
| ||||||||