logoalt Hacker News

silverwindyesterday at 5:41 AM2 repliesview on HN

Pinning actions doesn't really work because most action dependencies are unpinned thanks to npm default behaviour of not pinning them.


Replies

baobunyesterday at 8:18 AM

Just don't use actions which pull in arbitrary npm packages without a lockfile.

NamlchakKhandroyesterday at 8:56 AM

Why does this matter?

JavaScript actions are already bundled.