This action scans your repository's workflows for uses: references, checks the GitHub API for each action's latest release, and reports version drift or insecure tag pinning (e.g., pinning to v1 instead of a commit SHA).
security devops ci-cd semver dependency-management github-actions github-action supply-chain-security workflow-security outdated-actions
-
Updated
Jul 20, 2026 - Python