Unless you link using tags.
The GitHub Actions ecosystem found out the hard way, through some rather high-profile compromises. They hotfixed it by adding "immutable tags" to their platform, and are now working on adding a lockfile to... easily reference a commit hash.
repo can also rewrite existing commit and you again won't be able to retrieve it so switching to commit IDs only lowers the level of failure somewhat
> lowers the level of failure somewhat
congratulations on lack of ability to read with understanding
This seems weirdly aggressive and not nice.