# Pin GitHub Actions and reusable workflow refs to immutable SHAs before CI changes merge with pinact

> Rewrite mutable GitHub Actions refs to commit SHAs so workflow changes do not ship with drifting dependencies.

- Skill: `agentskillexchange/pin-github-actions-and-reusable-workflow-refs-to-immutable-s` (Agent Skill)
- Install (CLI): `npx skillmds@latest add agentskillexchange/pin-github-actions-and-reusable-workflow-refs-to-immutable-s`
- Raw SKILL.md: https://api.skillmd.com/api/skills/agentskillexchange/pin-github-actions-and-reusable-workflow-refs-to-immutable-s/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Productivity
- Author: agentskillexchange (https://skillmd.com/u/agentskillexchange)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/agentskillexchange/pin-github-actions-and-reusable-workflow-refs-to-immutable-s

---


# Pin GitHub Actions and reusable workflow refs to immutable SHAs before CI changes merge with pinact

Rewrite mutable GitHub Actions refs to commit SHAs so workflow changes do not ship with drifting dependencies.

## Prerequisites

pinact CLI, repository access to the target .github workflow files, and optional GitHub token access for API-backed pin resolution.

## Installation

Requirements and caveats from upstream:
- For tags, the commit's Committer.Date is checked (requires additional API call)

Basic usage or getting-started notes:
- $ pinact run
- sh
- pinact run [<workflow file>...]

- Source: https://github.com/suzuki-shunsuke/pinact
- Extracted from upstream docs: https://raw.githubusercontent.com/suzuki-shunsuke/pinact/HEAD/README.md

## Documentation

- https://github.com/suzuki-shunsuke/pinact

## Source

- [Agent Skill Exchange](https://agentskillexchange.com/skills/pin-github-actions-and-reusable-workflow-refs-to-immutable-shas-before-ci-changes-merge-with-pinact/)

