← Docs
How scanning and remediation works
Whenever you push a change to a repository's default branch, ActionLock checks whether the push touched anything under .github/workflows/:
- If it did, ActionLock scans your workflow files for any
uses:reference pointing at a mutable tag (like@v4) instead of a full commit SHA. - If it didn't, ActionLock instead re-checks every already-pinned reference across your workflows to see whether it's gone stale — see Keeping pins fresh.
When ActionLock finds something to fix, it opens a single pull request with the rewrites. If a fix PR is already open, new findings update that same PR rather than opening a duplicate.