Action-locker: pin, verify, and vendor GHAs
Single stdlib-only Python file means the supply chain tool has no supply chain.
A CLI tool to pin GitHub Actions to commit SHAs for supply-chain security.
Automates SHA pinning with --comment flag to preserve original tags inline.
DevOps engineers, security-conscious teams using GitHub Actions
StepSecurity/pin-github-action · manicminer/pin-github-action
Single stdlib-only Python file means the supply chain tool has no supply chain.
SBOMs for CI/CD pipelines catch transitive action deps that grep misses entirely.
Tarball diffing plus Claude analysis catches build.rs backdoors cargo-audit misses.
Dependabot alternative with AI test generation and supply chain poisoning checks.
NPM supply chain scanner competing against Socket, Snyk, and npm audit.
Dependabot already does this without the AI agent overhead.