https://github.com/actions/toolkit/blob/1b1e81526b802d1d641911393281c2fb45ed5f11/docs/action-versioning.md?plain=1#L9 This contradicts: https://docs.github.com/en/actions/security-for-github-actions/security-guides/security-hardening-for-github-actions#using-third-party-actions > You can help mitigate this risk by following these good practices: > >Pin actions to a full length commit SHA