home/categories/cicd/adaptive-enforcement-lab-claude-skills-skills-secure-action-pinning-overview-skill-md
cicddevops
action-pinning-overview
Why pinning GitHub Actions to SHA-256 commits matters for supply chain security. Attack vectors from unpinned actions and comparison of tag vs SHA pinning.
maintainer
adaptive-enforcement-lab
์
๋ฐ์ดํธ๋จ 1/5/2026
์คํ
0
ํฌํฌ
1
quick start
Installation and usage
Why pinning GitHub Actions to SHA-256 commits matters for supply chain security. Attack vectors from unpinned actions and comparison of tag vs SHA pinning.
์ค์น
$ install --globalskills.sh
์ฌ์ฉ๋ฒ
์ค์น ํ ํฐ๋ฏธ๋์์ ๋ค์ ๋ช ๋ น์ ์คํํ์ฌ ์ด ์คํฌ์ ์ฌ์ฉํ ์ ์์ต๋๋ค:
skills use action-pinning-overview