A gh CLI extension that generates and verifies the GitHub Actions dependency lockfile, pinning every action your workflows use to an exact commit.
-
Updated
Jul 31, 2026 - Go
A gh CLI extension that generates and verifies the GitHub Actions dependency lockfile, pinning every action your workflows use to an exact commit.
Pin your GitHub Actions. Prick holes in their supply chain security.
Tooling to manage the `pyodide-lock.json` file
The authoritative definition of the GitHub Actions dependency lockfile format, plus a Go parser for auditing and verifying the action pins in use across a repo's workflows.
Scripts to pin poetry and pipenv dependencies
Pin workflow dependency versions to full-length hashes.
Audit your GitHub Actions supply chain security with pinprick
Add a description, image, and links to the dependency-pinning topic page so that developers can more easily learn about it.
To associate your repository with the dependency-pinning topic, visit your repo's landing page and select "manage topics."