I got a couple of PRs this morning from this project https://github.com/getplumber/plumber that highlights GHAs with tags or branch refs instead of being pinned to SHAs. So far, they've only opened PRs on a couple of projects (HoneySQL and a Ruby project) but I suspect they'll be adding PRs to lots of other projects... Thoughts?
This has been a best practice for a while. I'm supportive
point_up::skin-tone-2 The CVE the PR references is https://github.com/advisories/GHSA-mrrh-fwg8-r2c3 for a bit more context. Tags on actions changed to point to malicious commit SHAs.