SHA pinning won't necessarily help if the dependency you are pinning doesn't pin its own dependencies! You still get stuff pulled via vulnerable tags etc. How long till we get this https://github.com/github/roadmap/issues/592 ...
They are actually releasing this very soon. I’ve seen some of my workflows use an immutable OCI image for some of GH’s actions like actions/checkout.
That protects from npm supply chain stuff, but obviously third-party includes like docker/build-push-action are still a risk.
The fact they've been stalling this for a good 2.5 years is... insane??