🔥 3-day streak
GitHub Actions (GH-200)61 / 142
Question 61 of 142
Your security team requires that all third-party actions used in workflows be protected against a maintainer force-pushing a malicious commit onto an existing tag. A developer currently references a community action as `some-org/deploy-action@v3`. Which reference change best satisfies the requirement while still guaranteeing the exact code you reviewed will run?
Reviewed for accuracy · Report an issueNext question