🔥 3-day streak
GitHub Actions (GH-200)101 / 142
Question 101 of 142
Your security team audits a workflow that uses a popular third-party action referenced as `uses: some-vendor/deploy-action@v3`. The team wants to protect the pipeline against a supply-chain attack in which the vendor's tag is repointed to a malicious commit, while still following GitHub's recommended practice for third-party actions. Which change should you make to the reference?
Reviewed for accuracy · Report an issueNext question