---
title: "pin-github-actions"
description: "The mechanizable slice of CI supply-chain hardening, enforced at two points: at commit (the git hook, over staged changes) and at agent tool-use (over a tool call's arguments, as the agent writes), a workflow that refere"
canonical: https://agentpluginsdirectory.com/plugins/pin-github-actions--open-coder-ai-6
last-updated: 2026-09-21
---

# pin-github-actions
The mechanizable slice of CI supply-chain hardening, enforced at two points: at commit (the git hook, over staged changes) and at agent tool-use (over a tool call's arguments, as the agent writes), a workflow that references a third-party GitHub Action by a movable ref, a branch or a version tag, instead of a full 40-character commit SHA. A tag like v4 or a branch like main can be re-pointed at new code after review, so the action that runs tomorrow need not be the one that was audited today; a compromised or rug-pulled release rides in on exactly that mutability. The gate blocks an added line that references an action by a non-SHA ref (owner/repo at a tag/branch); a full 40-char SHA pin passes, local actions (no ref) pass, and 'pragma: allowlist unpinned-action' on the same line is a visible, deliberate exception. This is the OpenSSF Scorecard Pinned-Dependencies control for the slice a diff can show; signature and provenance verification stay out of scope.
- Slug: pin-github-actions--open-coder-ai-6
- Publisher: chock-core
- Repository: https://github.com/open-coder-ai/chock
- Manifest: .agents/policies/pin-github-actions/plugin.json
- Version: 0.0.3
- License: Apache-2.0
- Category (editorial): other
- Skills: 1 (pin-github-actions)
- MCP servers: 0
- Stars: 7
- Repository created: 2026-08-17
- Repository last pushed: 2026-09-21
- Publisher type: Organization
- Listing: https://agentpluginsdirectory.com/plugins/pin-github-actions--open-coder-ai-6
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## Skills

- pin-github-actions: The mechanizable slice of CI supply-chain hardening, enforced at two points: at commit (the git hook, over staged changes) and at agent tool-use (over a tool call's arguments, as the agent writes), a workflow that references a third-party GitHub Action by a movable ref, a branch or a version tag, i…

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.
