# Pinning Third-Party Actions — GitHub Actions

Source: https://www.skillbyai.com/en/github-actions/x-pin

> Tags can move; commit SHAs cannot.

## Supply-chain risk of mutable tags

Referencing `some/action@v3` trusts whatever commit the tag points to now and in the future; if the action's repository is compromised, the tag can be moved to malicious code, as has happened in real incidents. Pin third-party actions to a **full commit SHA** (with the version in a comment), review updates with Dependabot or Renovate, prefer actions from verified creators, and restrict which actions are allowed at the organisation level. First-party actions/* are lower risk but can be pinned too.

## Tag versus SHA pinning

The SHA shown is a placeholder; use the real commit of the version you reviewed. Not run here.

```yaml
# mutable: the tag can be moved to different code later
- uses: some-org/deploy-action@v3

# immutable: this exact commit, version noted for humans and Dependabot
- uses: some-org/deploy-action@0123456789abcdef0123456789abcdef01234567  # v3.2.1
```

## Let Dependabot update pinned SHAs

Dependabot understands SHA pins with version comments and opens pull requests when new versions are released.

**Quiz:** Why pin actions to a commit SHA instead of a tag?

- [x] Tags can be moved to different code; a SHA always refers to the same code
- [ ] SHAs run faster
- [ ] Tags are not allowed
- [ ] SHAs include secrets

*Answer:* Tags can be moved to different code; a SHA always refers to the same code. Immutable references.
