Docs
A quick reference for how ActionLock scans, pins, and keeps your workflows SHA-pinned.
-
Installing ActionLock
The GitHub App, and the four permissions it requests.
-
How scanning and remediation works
What happens on every push, and when ActionLock opens a PR.
-
The pin comment format
Why the resolved tag stays visible as a trailing comment.
-
Keeping pins fresh
How already-pinned lines get re-checked for drift over time.
-
Opting a line out of automatic updates
The
ActionLock: no-opmarker, for staying on a specific SHA. -
Constraining updates to a semver range
Cap re-pinning to a range instead of full tracking or a full freeze.
-
Reviewing remediation PRs
What a real ActionLock pull request looks like.
-
Free vs. Pro
What's included today, and what's planned.
-
Need more help?
Where to go if something isn't behaving as documented.