Use action based on commit instead of branch/tag


Is it possible to use an action referring to its commit instead of branch or tag?

A branch can have its content changed, and a tag can be deleted and re-released. This means that if i am using an action in my workflow, and the owner by mistake (or maliciously) changes the content of the branch or tag, then, my workflow will be impacted by that. However, if you refer to the action using a commit, this will be inmutable and it will not be affected by any of the changes mentioned above (other than deleting the commit, of course)


1 Like

You can do that, example from the docs:

    - uses: actions/javascript-action@172239021f7ba04fe7327647b213799853a9eb89
1 Like