unidata/Verify GitHub Action SHA Pinning
Scans all workflow files to ensure all GitHub Actions are pinned to a valid SHA that exists on the default branch of the action's repository.
View on GitHubTrust Signals
- Scorecard Score
- not yet scored
- Maintenance Recency
- Stale
- License
- None
Inputs
| name | description | required | default |
|---|---|---|---|
| TOKEN | A GitHub TOKEN used to make API calls to GitHub via CURL | — | ${{ github.token }} |
Outputs
no outputs