原文
GitHub Actions has no built-in mechanism to lock dependency versions.
Version tags like @v4 can be silently retagged to point to different code.
Composite actions pull in transitive dependencies you can't see or audit.
原始链接: https://gh-actions-lockfile.net
GitHub Actions 没有内置机制来锁定依赖项版本。像 @v4 这样的版本标签可能会被静默地重新标记指向不同的代码。复合操作会引入您无法查看或审计的传递依赖项。
GitHub Actions has no built-in mechanism to lock dependency versions.
Version tags like @v4 can be silently retagged to point to different code.
Composite actions pull in transitive dependencies you can't see or audit.