Agreed. Good news is GitHub will address that with Immutable Releases https://github.blog/news-insights/product-news/whats-coming-... You won't even need to use commit SHA as long as the maintainer follows this approach.
What an absolute joke that it has taken GitHub this long to clean up it's act when it comes to supply chain security.
What an absolute joke that it has taken GitHub this long to clean up it's act when it comes to supply chain security.