They even closed the immutable action issue as a "wont fix" cause you know when it's too hard we all know the best way is to give up. Not like there wasany major security incident this year due to this /s
We use commit hashes to pin actions, have the version as a comment (e.g # v4) and renovate will keep both up to date in the PRs.
And there is a more or less recently added repository setting to require actions to be pinned to hashes.
Just pin your actions to shasum
tomeraberbach•1h ago
gjtorikian/gh-actions-lockfile@v1
Presumably since it has to run first it must run unpinned?
Elucalidavah•1h ago