|
|
|
|
|
by hermanb
1510 days ago
|
|
I’ve been wondering about this too and always used full sha’s until now. But recently I’ve made an action myself: You actually need to publish the action to the marketplace with each tag manually. It feels like there might be more going on. Is GitHub storing those published tags and avoiding tampering by only letting you use those tags once? Are they warning or blocking runs if you tamper? … I’m really curious because it seems like SUCH a giant risk otherwise. |
|