← ClaudeAtlas

pin-github-actionslisted

Supply-chain audit: verifies every GitHub Actions reference is pinned to a full commit SHA (not a mutable tag or branch), reports unpinned uses with evidence, and optionally rewrites them to SHA + version comment.
emaarco/hogwarts · ★ 0 · Code & Development · score 73
Install: claude install-skill emaarco/hogwarts
# Skill: pin-github-actions Audits a repository's GitHub Actions and verifies that **every action reference is pinned to a full-length commit SHA**. Mutable tags (`@v4`, `@v4.2.2`) and branches (`@main`) can be silently repointed by whoever controls the upstream repo — the [`tj-actions/changed-files` compromise (CVE-2025-30066, March 2025)](https://github.com/tj-actions/changed-files/security/advisories) repointed existing tags to a malicious commit that dumped CI secrets; only SHA-pinned consumers were unaffected. SHA pinning is the [GitHub-recommended hardening](https://docs.github.com/en/actions/security-for-github-actions/security-guides/security-hardening-for-github-actions#using-third-party-actions) and the OpenSSF Scorecard [`Pinned-Dependencies`](https://github.com/ossf/scorecard/blob/main/docs/checks.md#pinned-dependencies) check. Run this when asked to "check if actions are pinned", harden CI supply chain, or as the GitHub-Actions slice of a release/supply-chain audit (see the sibling skill **`release-audit`**). ## Pinning rule A reference is **pinned** only when the ref after `@` is a full 40-hex-character git commit SHA, ideally followed by a comment naming the human-readable version: ```yaml uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 ``` (The SHA/version above only illustrates the format — never copy it; resolve the current SHA fresh via the Phase 3 commands.) | Reference form | Verdict | |---|---| | `owner/repo@<40-hex-sha>`