Skip to main content

Build provenance: This package is built and distributed by Astral as part of astral-dev-toolchain. It packages pinact from tag v5.0.0 at commit a4f45e095b184794ac1f82b6b07cc35b0b8cfe7b.


pinact

Ask DeepWiki Install | Usage | Configuration | Agent Skill

pinact is a CLI to pin GitHub Actions and Reusable Workflows. pinact can also update their versions and verify version comments.

$ pinact run
.github/workflows/test.yaml:8
-       - uses: actions/checkout@83b7061638ee4956cf7545a6f7efe594e5ad0247 # v3
+       - uses: actions/checkout@83b7061638ee4956cf7545a6f7efe594e5ad0247 # v3.5.1
.github/workflows/test.yaml:9
-       - uses: actions/setup-go@v4
+       - uses: actions/setup-go@7b8cf10d4e4a01d4992d18a89f4d7dc5a3e6d6f4 # v4.3.0
.github/workflows/test.yaml:10
-       - uses: actions/cache@v3.3.1
+       - uses: actions/cache@88522ab9f39a2ea568f7027eddc7d8d8bc9d59c8 # v3.3.1
.github/workflows/test.yaml:16
-     uses: suzuki-shunsuke/actionlint-workflow/.github/workflows/actionlint.yaml@v0.5.0
+     uses: suzuki-shunsuke/actionlint-workflow/.github/workflows/actionlint.yaml@b6a5f966d4504893b2aeb60cf2b0de8946e48504 # v0.5.0

Features

  1. Pin GitHub Actions and Reusable Workflows
  2. Check if actions are pinned without editing files
  3. Offline check without GitHub API
  4. Update actions with a minimum release age
  5. Verify version comments
  6. Require a version comment on SHA-pinned actions
  7. Verify if actions meet the minimum release age
  8. Pin branches
  9. Include and exclude specific actions
  10. Generate SARIF. This is useful to create reviews using reviewdog
  11. Read GitHub access token via keyrings or ghtkn
  12. Pin only changed lines
  13. Support GitHub Enterprise Server
  14. GitHub Action

Getting Started

  1. Install pinact

  2. Pin the actions of a repository:

pinact run

Without an argument, pinact pins the workflow files and the action files of the repository; Usage lists them and shows how to pin actions written in a document such as README.md.

  1. Check them in CI instead of fixing them:
pinact run --check

The run exits with a non-zero code when something needs pinning. Checking without fixing covers --check, --fix=false, and the offline check --no-api.

  1. Pass a GitHub access token so the API calls aren't rate limited:
export GITHUB_TOKEN=<your token>

pinact can also read the token from the OS keyring or from ghtkn.

  1. Optionally, write a configuration file:
pinact init

The configuration file is optional. It says which files to pin, which actions to ignore, and what the default minimum release age is. See Configuration File.

Installing the Agent Skill

pinact ships a single skill. It holds no documentation of its own: it tells the coding agent to read the documentation embedded in the pinact binary with pinact docs list and pinact docs show <name>, so the agent always reads the documentation of the version it is actually running.

gh skill install:

gh skill install suzuki-shunsuke/pinact pinact

Documentation

The documentation is split by topic under docs/. These documents are embedded in the pinact binary, so pinact docs list and pinact docs show <name> (pinact >= v5.0.0) serve exactly what is listed below, matching the version that is installed. They are the single source of truth, shared between this README, the embedded documentation, and the skill, so there's no duplicated maintenance.

pinact docs list # The name and the description of every document, as JSON
pinact docs show config # One document
pinact docs show codes/005 # A document in a subdirectory is named by its path

USAGE.md is the help of every command, generated from the CLI itself.

GitHub Actions

https://github.com/suzuki-shunsuke/pinact-action

We develop GitHub Actions to pin GitHub Actions and reusable workflows by pinact.

Motivation

It is a good manner to pin GitHub Actions versions by commit hash. GitHub tags are mutable so they have a substantial security and reliability risk.

See also Security hardening for GitHub Actions - GitHub Docs

Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps mitigate the risk of a bad actor adding a backdoor to the action's repository, as they would need to generate a SHA-1 collision for a valid Git object payload

👍

uses: actions/cache@88522ab9f39a2ea568f7027eddc7d8d8bc9d59c8 # v3.3.1

👎

uses: actions/cache@v3
uses: actions/cache@v3.3.1

Why not using Renovate's helpers:pinGitHubActionDigestsToSemver preset?

The Renovate preset helpers:pinGitHubActionDigestsToSemver is useful, but pinact is still useful: You can use both the preset and pinact together.

  1. Renovate can't pin actions in pull requests before merging them. If you use linters such as ghalint in CI, you need to pin actions before merging pull requests (ref. ghalint policy to enforce actions to be pinned)
  2. Even if you use Renovate, sometimes you would want to update actions manually
  3. pinact is useful for non Renovate users
  4. pinact supports verifying version annotations

See also

Release files for astral-dev-toolchain-pinact 5.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distributions (wheels)

Table of built distributions (wheels) for astral-dev-toolchain-pinact 5.0.0
File
astral_dev_toolchain_pinact-5.0.0-py3-none-win_arm64.whl Python 3 none Windows ARM64 Details
astral_dev_toolchain_pinact-5.0.0-py3-none-win_amd64.whl Python 3 none Windows x86-64 Details
astral_dev_toolchain_pinact-5.0.0-py3-none-manylinux_2_17_x86_64.whl Python 3 none Linux glibc 2.17+ x86-64 Details
astral_dev_toolchain_pinact-5.0.0-py3-none-manylinux_2_17_aarch64.whl Python 3 none Linux glibc 2.17+ ARM64 Details
astral_dev_toolchain_pinact-5.0.0-py3-none-macosx_13_0_x86_64.whl Python 3 none macOS 13.0+ x86-64 Details
astral_dev_toolchain_pinact-5.0.0-py3-none-macosx_13_0_arm64.whl Python 3 none macOS 13.0+ ARM64 Details

Total release size: 33.1 MB

Release files / astral_dev_toolchain_pinact-5.0.0-py3-none-win_arm64.whl

Download URL astral_dev_toolchain_pinact-5.0.0-py3-none-win_arm64.whl
Size 5.2 MB
Tags Python 3 Windows ARM64
SHA-256 checksum
How to use checksums
bee1c2e294cbbfedfebc758d16d858c65db77dc30d62e500dbfd291bf6755d8c
BLAKE2b-256 checksum
How to use checksums
6c0147535246a8f76199b279d18c999d2aef3c7ebbc282d42d422139ff7cdcb2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.19 {"installer":{"name":"uv","version":"0.12.19","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 28, 2026.

Transparency log

Release files / astral_dev_toolchain_pinact-5.0.0-py3-none-win_amd64.whl

Download URL astral_dev_toolchain_pinact-5.0.0-py3-none-win_amd64.whl
Size 5.8 MB
Tags Python 3 Windows x86-64
SHA-256 checksum
How to use checksums
3b5cd2a2d6bcc8e0697f11c7a49a5e50a28517f4fec0fcf37386fc95dc33d8ff
BLAKE2b-256 checksum
How to use checksums
db491594385a2909ff3c9078442bf628e08b0733ac45fc43596bdf8bc03c795d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.19 {"installer":{"name":"uv","version":"0.12.19","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 28, 2026.

Transparency log

Release files / astral_dev_toolchain_pinact-5.0.0-py3-none-manylinux_2_17_x86_64.whl

Download URL astral_dev_toolchain_pinact-5.0.0-py3-none-manylinux_2_17_x86_64.whl
Size 5.9 MB
Tags Linux glibc 2.17+ x86-64 Python 3
SHA-256 checksum
How to use checksums
91a63da8ce82cec0d180d5ff92c1d2960edf8772ebf1d4728b34c2aa19378aff
BLAKE2b-256 checksum
How to use checksums
d83852d191f51d24f63590df1f33cc37cce1b040b4e4b40b0b3e7d5d8506bb23
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.19 {"installer":{"name":"uv","version":"0.12.19","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 28, 2026.

Transparency log

Release files / astral_dev_toolchain_pinact-5.0.0-py3-none-manylinux_2_17_aarch64.whl

Download URL astral_dev_toolchain_pinact-5.0.0-py3-none-manylinux_2_17_aarch64.whl
Size 5.2 MB
Tags Linux glibc 2.17+ ARM64 Python 3
SHA-256 checksum
How to use checksums
04565e1613ebebac88bb65cef72e7441c0f7369ab03c2dd2cdd647cf7bebe4af
BLAKE2b-256 checksum
How to use checksums
0a719fffc879450d975cd0838259b3fc54401b819286be21687265ca16ee72bf
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.19 {"installer":{"name":"uv","version":"0.12.19","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 28, 2026.

Transparency log

Release files / astral_dev_toolchain_pinact-5.0.0-py3-none-macosx_13_0_x86_64.whl

Download URL astral_dev_toolchain_pinact-5.0.0-py3-none-macosx_13_0_x86_64.whl
Size 5.7 MB
Tags Python 3 macOS 13.0+ x86-64
SHA-256 checksum
How to use checksums
464680f41b2b6ea3522c72997922241f39372154e288d9bdc40d7d53cacc6a6f
BLAKE2b-256 checksum
How to use checksums
f85c80c4db15439038e2a7b9aa3945cf50fc6dd65ab1b663f5e881079e6ef181
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.19 {"installer":{"name":"uv","version":"0.12.19","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 28, 2026.

Transparency log

Release files / astral_dev_toolchain_pinact-5.0.0-py3-none-macosx_13_0_arm64.whl

Download URL astral_dev_toolchain_pinact-5.0.0-py3-none-macosx_13_0_arm64.whl
Size 5.4 MB
Tags Python 3 macOS 13.0+ ARM64
SHA-256 checksum
How to use checksums
d22d7e575d83694563ebf58d92310c25a9b9d115ee0179276eb95b62b0133ffa
BLAKE2b-256 checksum
How to use checksums
90ffc1dda796279c54e5bbd4488d0077de6ef24b34bea61d01b729c51ce42692
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.19 {"installer":{"name":"uv","version":"0.12.19","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 28, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

5.0.0 This release

6 release files

4.1.1

6 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page