jongalloway/action-pinner

Scan and pin unpinned GitHub Actions references to commit SHAs.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
modeMode to run (scan|fix|enforce|pr)noscan
configPath to .action-pinner.jsonno.action-pinner.json
pathWorkflow file, directory, or glob to scanno
exclude_pathWorkflow file, directory, or glob to excludeno
include_actionComma-separated or newline-delimited action patterns to includeno
exclude_actionComma-separated or newline-delimited action patterns to excludeno
allow_actionsComma-separated or newline-delimited enforcement allowlist patternsno
exception_rulesComma-separated or newline-delimited enforcement exception rules (<action>[@ref][::workflow-glob])no
jsonEmit JSON outputnofalse
namedescription
compliantWhether enforcement completed without violations or invalid exceptions
allowed_countNumber of unpinned refs allowed by allowlists or exceptions
violation_countNumber of violating unpinned refs
invalid_exception_countNumber of malformed or expired exceptions
fingerprintDeterministic run fingerprint
config_hashDeterministic config hash