{"repo":"github/gh-actions-lock","free":true,"listed":false,"github":"https://github.com/github/gh-actions-lock","clone":"git clone https://github.com/github/gh-actions-lock.git","description":"A gh CLI extension that generates and verifies the GitHub Actions dependency lockfile, pinning every action your workflows use to an exact commit.","language":"Go","stars":31,"topics":["cli","dependency-pinning","gh-extension","github-actions","go","lockfile","security","supply-chain-security"],"license":"MIT","category":"cli-tools","readme_excerpt":"gh-actions-lock Lock your workflow dependencies. [!WARNING] Technical Preview. gh-actions-lock is pre-1.0 and under active development. The lockfile format, command flags, and behavior may change without notice between releases. Use it, file issues, and expect rough edges. Background gh-actions-lock is part of GitHub's Workflow Dependency Pinning effort. It gives repositories a lockfile that pins every workflow dependency to a verified commit, so what runs on the runner is exactly what you locked. Development is ongoing and behavior may still change. Contributions are welcome. See CONTRIBUTING.md to get started. Requirements Requires the gh CLI. Install it first, then install the extension: Usage Scan every workflow under .github/workflows/ directory, pin each resolvable action to a SHA, and update the lockfile: After the initial run to onboard workflows, you will need to run gh actions-lock when: - A new workflow is created that has uses dependencies. - An existing workflow adds or removes uses dependencies. A full-directory run ( gh actions-lock with no path arguments) also prunes lockfile entries for workflows that have been deleted from .github/workflows/ , dropping any dependencies left orphaned by the removal. Scoped runs that name specific workflows never prune out-of-scope entries. Pins to branches or partial versions (e.g. main , v4 ) are trusted from the lockfile and not re-resolved on a normal run. To bump them to the current upstream commit, run: --relock re-resol","default_branch":null,"files":null,"tree":[],"storefront":"/r/github","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/github/gh-actions-lock/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}