1- # gh-actions-pin
1+ # gh-actions-lock
22
33Manage your workflow dependencies.
44
55## Install
66
77``` bash
8- gh extension install github/gh-actions-pin
8+ gh extension install github/gh-actions-lock
99```
1010
1111## Usage
@@ -14,27 +14,27 @@ Scan every workflow under `.github/workflows/` and pin what it can -- pinning
1414each resolvable action to an immutable SHA and updating the lockfile:
1515
1616``` bash
17- gh actions-pin
17+ gh actions-lock
1818```
1919
2020Scope the scan to a single workflow (same default behavior, one file):
2121
2222``` bash
23- gh actions-pin .github/workflows/ci.yml
23+ gh actions-lock .github/workflows/ci.yml
2424```
2525
2626By default, already-pinned workflows are trusted from the lockfile -- their
2727reachability isn't re-checked against upstream. To force a full re-verification
2828of every recorded pin (bypassing that fast path):
2929
3030``` bash
31- gh actions-pin --rescan
31+ gh actions-lock --rescan
3232```
3333
3434Read-only check for CI (reports findings, writes nothing):
3535
3636``` bash
37- gh actions-pin --no-fix --json=valid,findings
37+ gh actions-lock --no-fix --json=valid,findings
3838```
3939
4040` --no-fix ` controls whether fixes are applied; ` --json ` only selects the output
@@ -45,12 +45,12 @@ format. Structured results go to stdout, progress to stderr.
4545GitHub Actions is a package manager that forgot to ship a lockfile. Your
4646workflows are the manifest -- every ` uses: ` line is a dependency, resolved by
4747mutable tag or branch * at runtime* , on GitHub's servers, with no record of what
48- actually ran. ` gh-actions-pin ` supplies the missing half: ` .github/workflows/actions.lock ` ,
48+ actually ran. ` gh-actions-lock ` supplies the missing half: ` .github/workflows/actions.lock ` ,
4949the Actions analogue of ` go.sum ` or ` package-lock.json ` . Each run resolves every
5050direct and transitive dependency to an immutable commit SHA, locks it, and
5151verifies the lock hasn't been tampered with before any of it runs.
5252
53- A single ` gh actions-pin ` invocation walks two paths. The ** verify** path is
53+ A single ` gh actions-lock ` invocation walks two paths. The ** verify** path is
5454read-only and always runs: it scans every workflow, resolves each dependency to
5555a commit SHA, and checks the result against the lockfile. The ** fix** path
5656applies pins — rewriting ` uses: ` lines and updating the lockfile — for the
@@ -59,7 +59,7 @@ past in the spinner.
5959
6060``` mermaid
6161flowchart TD
62- Start([gh actions-pin ]) --> Scan
62+ Start([gh actions-lock ]) --> Scan
6363
6464 subgraph verify["VERIFY · read-only diagnosis"]
6565 direction TB
@@ -88,7 +88,7 @@ flowchart TD
8888The security guarantee lives in ** Verifying reachability** : a SHA pin is only
8989trustworthy if that commit is reachable from the tag/branch it claims to come
9090from. A SHA that resolves but isn't in the ref's history is an * impostor commit*
91- -- the fork-network attack ` gh-actions-pin ` exists to catch -- and it's flagged
91+ -- the fork-network attack ` gh-actions-lock ` exists to catch -- and it's flagged
9292rather than silently trusted.
9393
9494## Development
@@ -114,6 +114,6 @@ sides pick them up.
114114| Variable | Purpose |
115115| ---| ---|
116116| ` GH_TOKEN ` / ` GITHUB_TOKEN ` | Auth token for live tests (falls back to ` gh auth token ` ) |
117- | ` GH_ACTIONS_PIN_WORKFLOWS_DIR ` | Override the workflows directory to scan (lab/testing use) |
117+ | ` GH_ACTIONS_LOCK_WORKFLOWS_DIR ` | Override the workflows directory to scan (lab/testing use) |
118118| ` KEEP_FIXTURES ` | Keep temp dirs after test runs for debugging |
119119
0 commit comments