logoalt Hacker News

g947oyesterday at 11:30 AM1 replyview on HN

How does this lock down transitive dependencies? Is it effective if the action you rely on doesn't pin its dependencies?


Replies

baobunyesterday at 11:59 AM

You don't use actions pulling in unpinned dependencies outside of trusted distro package manager at runtime.

I believe this problem is probably overstated. Can you point us to such an action you are concerned with that has either transitive actions dependency or unlocked npm dependencies where maintainers aren't responsive to addressing PRs to illustrate?