Securing the CI/CD Supply Chain: New Tool Locks Down GitHub Actions Dependencies
A new open-source tool addresses critical security gaps in GitHub Actions by generating verifiable lockfiles that pin dependencies to exact commit SHAs with integrity hashes, tackling mutable tags and hidden transitive dependencies.