Terms of Service
Last updated: August 18, 2026
These Terms of Service ("Terms") govern your use of ActionLock (the "Service," "we," "us"), a GitHub App. By installing or using ActionLock, you agree to these Terms. If you're installing on behalf of an organization, you're agreeing on that organization's behalf and confirming you have authority to do so.
1. The Service
ActionLock scans GitHub Actions workflow files in repositories where it's installed, detects Actions referenced by mutable version tags instead of full commit SHAs, and opens pull requests to remediate them. Paid plans additionally provide an ongoing enforcement status check. Feature availability by plan is described on our Pricing page, which may change over time.
2. Accounts and installation
You must have appropriate permissions on a GitHub organization or repository to install ActionLock there. You're responsible for the GitHub permissions you grant the App and for reviewing pull requests ActionLock opens before merging them — ActionLock does not merge changes on your behalf.
3. Billing
All paid plans are billed exclusively through GitHub Marketplace. Upgrades, downgrades, proration, and cancellations are handled by GitHub Marketplace's billing system, not by us directly. Refunds, where applicable, follow GitHub Marketplace's own policies.
4. Acceptable use
You agree not to: use the Service to violate any law; attempt to disrupt, reverse-engineer, or gain unauthorized access to the Service's infrastructure; or use the Service against repositories or organizations you don't have authorization to modify.
5. Disclaimer of warranty
ActionLock is provided "as is," without warranty of any kind, express or implied. We do not guarantee that ActionLock will detect every unpinned Action, that remediation pull requests will be free of errors, or that the Service will be uninterrupted. You are responsible for reviewing all pull requests before merging them into your codebase.
6. Limitation of liability
To the maximum extent permitted by law, we are not liable for any indirect, incidental, special, or consequential damages arising from your use of the Service, including damages resulting from a merged pull request, a missed detection, or a service interruption. Our total liability for any claim relating to the Service is limited to the amount you paid us, if any, in the 12 months preceding the claim.
7. Termination
You may uninstall ActionLock at any time from your GitHub organization or repository settings. We may suspend or terminate access to the Service for accounts that violate these Terms, with notice where practicable.
8. Changes to these Terms
We may update these Terms as the Service evolves. Continued use of ActionLock after a change constitutes acceptance of the updated Terms. Material changes will be reflected by updating the "Last updated" date above.
9. Contact
Questions about these Terms can be sent via Support.