GitHub Actions not pinned to a full commit SHA

Pin external actions to a verified full commit SHA to reduce unexpected changes to the referenced code.

Description

When a GitHub Actions workflow references an external action only by a tag or branch, that name can be moved to a different commit. The same workflow configuration can therefore run unreviewed action code at a later time.

A full-length commit SHA fixes the code referenced in the action repository. It does not make other dependencies downloaded during execution or the workflow’s permissions safe.

Potential impact

  • Changes to an external action repository can cause unreviewed code to run in CI.
  • Retargeted tags or malicious changes can expose the workflow to supply-chain attacks.
  • Results can change over time, reducing reproducibility and auditability.

Remediation

Pin external action uses: references to verified full-length commit SHAs. Confirm that the SHA belongs to the reviewed version in the original repository, and replace it explicitly after validating an update. Review workflow permissions and the action’s other dependencies separately.

Examples

These excerpts compare reference formats using a historical action version. For actual use, review a supported version and separately configure required message inputs, token permissions and other settings.

Before

yaml
name: ci
on:
  pull_request:

jobs:
  comment:
    runs-on: ubuntu-latest
    steps:
      - name: Add comment
        uses: thollander/actions-comment-pull-request@v2

After

yaml
name: ci
on:
  pull_request:

jobs:
  comment:
    runs-on: ubuntu-latest
    steps:
      - name: Add comment
        uses: thollander/actions-comment-pull-request@b07c7f86be67002023e6cb13f57df3f21cdd3411

The after-example references a specific commit instead of a tag. Review the safety of that commit; SHA pinning does not automatically apply later security updates.

References