GitHub Actions locks workflow dependencies and scopes secrets to break supply chain attacks
After the tag-repositioning attacks that hit tj-actions and 23,000 repositories, GitHub is rolling out a security roadmap for Actions: dependency lockfiles, scoped secrets, and an egress firewall. Two measures are available today: SHA pinning and OIDC.