pkg.soopen package index

brew / Rang 2186

pinact mit Homebrew, MacPorts, Nix, zypper, winget installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für pinact in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install pinact

local Homebrew formula metadata

MacPortsverifiziert · 94%
sudo port install pinact

MacPorts ports tree · security/pinact/Portfile · Quelle: api.github.com

Linux

Nixverifiziert · 92%
nix profile install nixpkgs#pinact

nixpkgs package indexes · pkgs/by-name/pi/pinact/package.nix · Quelle: api.github.com

openSUSE zypperverifiziert · 92%
sudo zypper install pinact

openSUSE Tumbleweed package metadata · pinact · Quelle: download.opensuse.org

Windows

Windows Package Managerverifiziert · 92%
winget install --id suzuki-shunsuke.pinact -e

Windows Package Manager source index · suzuki-shunsuke.pinact · Quelle: cdn.winget.microsoft.com

Überblick

Paketzusammenfassung

Pins GitHub Actions to full hashes and versions

Befehle und Aliase

  • pinact

Verlauf

Projektgeschichte und Nutzung

pinact is a command-line supply-chain tool that pins GitHub Actions and reusable workflows to full commit hashes, updates them, and validates their version annotations.

Projektgeschichte

Shunsuke Suzuki developed pinact as a focused command-line editor and validator for GitHub Actions workflows and composite actions. Its scope expanded beyond initial pinning to updating actions, checking annotations, processing reusable workflows, emitting SARIF, enforcing minimum release ages, and supporting configurable policy rules.

Adoptionsgeschichte

The input records distribution through Homebrew, MacPorts, Nix, openSUSE, and Windows Package Manager. Its check-only and SARIF modes also make it suitable for CI enforcement as well as local rewriting.

Wie es verwendet wird

Run `pinact run` to process conventional workflow and action paths, or pass explicit files. `-check` validates without editing, `-no-api` performs an offline full-SHA syntax check, and `-update` resolves newer versions. API-backed operations can use a GitHub access token to avoid anonymous rate limits.

Warum Paket-Nerds sich dafür interessieren

pinact packages a concrete supply-chain hardening practice: replacing mutable GitHub Action tags with immutable full commit hashes while retaining version annotations for readability. It is useful both as a migration tool and as a policy check in continuous integration.

Zeitleiste

  • Initial scope: Pin GitHub Actions references to immutable full commit hashes.
  • Later development: Added updating, check-only and offline validation, SARIF output, minimum-release-age checks, and global configuration.

Related projects

  • GitHub Actions workflow and composite-action files are pinact's primary inputs.
  • reviewdog and GitHub code scanning can consume pinact's SARIF output.
  • GitHub's API supplies release, tag, and commit information used for resolution.

Sicherheitslage

Noch keine Protected-Tool-Abdeckung gefunden

Für pinact wurde kein passendes lokales Secret-Handling-Manifest gefunden. Paketmetadaten bleiben hier veröffentlicht, damit künftige Abdeckung eine stabile Paket-URL hat.

Installationsverhalten

  • In den Formelmetadaten ist kein Homebrew-Post-install-Hook erfasst.
  • Homebrew-Bottle-Metadaten sind für 6 Plattformziele verfügbar.
  • Build-Metadaten listen 1 Build-Abhängigkeiten.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
./.pinact.yaml./.github/pinact.yaml./.pinact.yml./.github/pinact.yml

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
pinactcliglobales Executable

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-09-19
Manager-Version5.0.0
Manager aktualisiert2026-09-12
lokale DatenOK
Upstreamaktuell
neueste erkannte Versionv4.1.1

https://github.com/suzuki-shunsuke/pinact

  • OKEs wurden keine Aktualitätswarnungen generiert.

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:pinact
Version5.0.0
PaketmanagerHomebrew
Paketmanager-Seitehttps://formulae.brew.sh/formula/pinact
Homepagehttps://github.com/suzuki-shunsuke/pinact
Repositoryhttps://github.com/suzuki-shunsuke/pinact
LizenzMIT
Quellarchivhttps://github.com/suzuki-shunsuke/pinact/archive/refs/tags/v4.1.1.tar.gz
Zuletzt aktualisiert2026-09-12T06:03:14Z
Pulseupdated
Build-Abhängigkeitengo
Bottleverfügbar (auf arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnicht definiert
Dienstkeiner deklariert

Registry-Fakten

Details aus der Quelldatenbank

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namepinact
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

Source-Datenbank-Treffer

Andere Paketmanager-Einträge

Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.

Nix95%

pinact

nix profile install nixpkgs#pinact
  • normalized package name match
  • Abgeglichen nach: Pinact
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/pi/pinact/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
zypper95%

pinact 4.1.1-1.1

CLI to edit GitHub Workflows and pin versions of Actions and Reusable Workflows

https://github.com/suzuki-shunsuke/pinact

sudo zypper install pinact
  • License: MIT
  • Category: Unspecified
  • Architecture: x86_64
  • Source Package: pinact
  • 1 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Pinact
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: pinact from https://download.opensuse.org/tumbleweed/repo/oss/repodata/d310d5a96106e1e8872a385adf98aaa23be9db5d80937a6717314e7e7f37715065c6c748ab7ccee6475d620b46979c0fe64235fc0c46988e17edf659578fcf31-primary.xml.zst
zypper95%

pinact-bash-completion 4.1.1-1.1

Bash Completion for pinact

https://github.com/suzuki-shunsuke/pinact

sudo zypper install pinact-bash-completion
  • License: MIT
  • Category: System/Shells
  • Architecture: noarch
  • Source Package: pinact
  • 2 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Pinact
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: pinact-bash-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/d310d5a96106e1e8872a385adf98aaa23be9db5d80937a6717314e7e7f37715065c6c748ab7ccee6475d620b46979c0fe64235fc0c46988e17edf659578fcf31-primary.xml.zst
zypper95%

pinact-fish-completion 4.1.1-1.1

Fish Completion for pinact

https://github.com/suzuki-shunsuke/pinact

sudo zypper install pinact-fish-completion
  • License: MIT
  • Category: System/Shells
  • Architecture: noarch
  • Source Package: pinact
  • 2 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Pinact
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: pinact-fish-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/d310d5a96106e1e8872a385adf98aaa23be9db5d80937a6717314e7e7f37715065c6c748ab7ccee6475d620b46979c0fe64235fc0c46988e17edf659578fcf31-primary.xml.zst
zypper95%

pinact-zsh-completion 4.1.1-1.1

Zsh Completion for pinact

https://github.com/suzuki-shunsuke/pinact

sudo zypper install pinact-zsh-completion
  • License: MIT
  • Category: System/Shells
  • Architecture: noarch
  • Source Package: pinact
  • 2 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Pinact
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: pinact-zsh-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/d310d5a96106e1e8872a385adf98aaa23be9db5d80937a6717314e7e7f37715065c6c748ab7ccee6475d620b46979c0fe64235fc0c46988e17edf659578fcf31-primary.xml.zst
MacPorts95%

pinact

sudo port install pinact
  • normalized package name match
  • Abgeglichen nach: Pinact
MacPorts ports tree · api.github.com · MacPorts ports tree: security/pinact/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1
winget95%

suzuki-shunsuke.pinact

winget install --id suzuki-shunsuke.pinact -e
  • normalized package name match
  • Abgeglichen nach: Pinact
Windows Package Manager source index · cdn.winget.microsoft.com · Windows Package Manager source index: suzuki-shunsuke.pinact from https://cdn.winget.microsoft.com/cache/source.msix

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment
  • pkg.so package database
  • pkgdb category and tag curation