macOS
brew install pinactlocal Homebrew formula metadata
sudo port install pinactMacPorts ports tree · security/pinact/Portfile · Quelle: api.github.com
brew / Rang 2186
Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für pinact in AI-Agent-Workflows.
Installation
brew install pinactlocal Homebrew formula metadata
sudo port install pinactMacPorts ports tree · security/pinact/Portfile · Quelle: api.github.com
nix profile install nixpkgs#pinactnixpkgs package indexes · pkgs/by-name/pi/pinact/package.nix · Quelle: api.github.com
sudo zypper install pinactopenSUSE Tumbleweed package metadata · pinact · Quelle: download.opensuse.org
winget install --id suzuki-shunsuke.pinact -eWindows Package Manager source index · suzuki-shunsuke.pinact · Quelle: cdn.winget.microsoft.com
Überblick
Pins GitHub Actions to full hashes and versions
Verlauf
pinact is a command-line supply-chain tool that pins GitHub Actions and reusable workflows to full commit hashes, updates them, and validates their version annotations.
Shunsuke Suzuki developed pinact as a focused command-line editor and validator for GitHub Actions workflows and composite actions. Its scope expanded beyond initial pinning to updating actions, checking annotations, processing reusable workflows, emitting SARIF, enforcing minimum release ages, and supporting configurable policy rules.
The input records distribution through Homebrew, MacPorts, Nix, openSUSE, and Windows Package Manager. Its check-only and SARIF modes also make it suitable for CI enforcement as well as local rewriting.
Run `pinact run` to process conventional workflow and action paths, or pass explicit files. `-check` validates without editing, `-no-api` performs an offline full-SHA syntax check, and `-update` resolves newer versions. API-backed operations can use a GitHub access token to avoid anonymous rate limits.
pinact packages a concrete supply-chain hardening practice: replacing mutable GitHub Action tags with immutable full commit hashes while retaining version annotations for readability. It is useful both as a migration tool and as a policy check in continuous integration.
Sicherheitslage
Für pinact wurde kein passendes lokales Secret-Handling-Manifest gefunden. Paketmetadaten bleiben hier veröffentlicht, damit künftige Abdeckung eine stabile Paket-URL hat.
Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.
local files
These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.
Config paths the tool may read or write during local use.
./.pinact.yaml./.github/pinact.yaml./.pinact.yml./.github/pinact.ymlExecutables
| Befehl | Art | Sichtbarkeit | Hinweis |
|---|---|---|---|
pinact | cli | globales Executable |
Aktualität
Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.
https://github.com/suzuki-shunsuke/pinact
Installationsmetadaten
| Paketschlüssel | brew:pinact |
|---|---|
| Version | 5.0.0 |
| Paketmanager | Homebrew |
| Paketmanager-Seite | https://formulae.brew.sh/formula/pinact |
| Homepage | https://github.com/suzuki-shunsuke/pinact |
| Repository | https://github.com/suzuki-shunsuke/pinact |
| Lizenz | MIT |
| Quellarchiv | https://github.com/suzuki-shunsuke/pinact/archive/refs/tags/v4.1.1.tar.gz |
| Zuletzt aktualisiert | 2026-09-12T06:03:14Z |
| Pulse | updated |
| Build-Abhängigkeiten | go |
| Bottle | verfügbar (auf arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux) |
| Homebrew post-install | nicht definiert |
| Dienst | keiner deklariert |
Registry-Fakten
| Source Database | Homebrew formula API |
|---|---|
| Tap | homebrew/core |
| Full Name | pinact |
| Version Scheme | 0 |
| Revision | 0 |
| Head Version | HEAD |
| Bottle Stable Root URL | https://ghcr.io/v2/homebrew/core |
| Deprecated | no |
| Disabled | no |
| Keg Only | no |
| URL Keys |
|
Source-Datenbank-Treffer
Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.
pinact
nix profile install nixpkgs#pinactpinact 4.1.1-1.1
CLI to edit GitHub Workflows and pin versions of Actions and Reusable Workflows
https://github.com/suzuki-shunsuke/pinact
sudo zypper install pinactpinact-bash-completion 4.1.1-1.1
Bash Completion for pinact
https://github.com/suzuki-shunsuke/pinact
sudo zypper install pinact-bash-completionpinact-fish-completion 4.1.1-1.1
Fish Completion for pinact
https://github.com/suzuki-shunsuke/pinact
sudo zypper install pinact-fish-completionpinact-zsh-completion 4.1.1-1.1
Zsh Completion for pinact
https://github.com/suzuki-shunsuke/pinact
sudo zypper install pinact-zsh-completionpinact
sudo port install pinactsuzuki-shunsuke.pinact
winget install --id suzuki-shunsuke.pinact -eQuellspur
Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.
View the package source record on GitHub.