macOS
brew install pinactlocal Homebrew formula metadata
sudo port install pinactMacPorts ports tree · security/pinact/Portfile · ソース: api.github.com
brew / 順位 2186
pinact のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。
インストール
brew install pinactlocal Homebrew formula metadata
sudo port install pinactMacPorts ports tree · security/pinact/Portfile · ソース: api.github.com
nix profile install nixpkgs#pinactnixpkgs package indexes · pkgs/by-name/pi/pinact/package.nix · ソース: api.github.com
sudo zypper install pinactopenSUSE Tumbleweed package metadata · pinact · ソース: download.opensuse.org
winget install --id suzuki-shunsuke.pinact -eWindows Package Manager source index · suzuki-shunsuke.pinact · ソース: cdn.winget.microsoft.com
概要
Pins GitHub Actions to full hashes and versions
履歴
pinact is a command-line supply-chain tool that pins GitHub Actions and reusable workflows to full commit hashes, updates them, and validates their version annotations.
Shunsuke Suzuki developed pinact as a focused command-line editor and validator for GitHub Actions workflows and composite actions. Its scope expanded beyond initial pinning to updating actions, checking annotations, processing reusable workflows, emitting SARIF, enforcing minimum release ages, and supporting configurable policy rules.
The input records distribution through Homebrew, MacPorts, Nix, openSUSE, and Windows Package Manager. Its check-only and SARIF modes also make it suitable for CI enforcement as well as local rewriting.
Run `pinact run` to process conventional workflow and action paths, or pass explicit files. `-check` validates without editing, `-no-api` performs an offline full-SHA syntax check, and `-update` resolves newer versions. API-backed operations can use a GitHub access token to avoid anonymous rate limits.
pinact packages a concrete supply-chain hardening practice: replacing mutable GitHub Action tags with immutable full commit hashes while retaining version annotations for readability. It is useful both as a migration tool and as a policy check in continuous integration.
セキュリティ状態
pinact に一致するローカルシークレット処理マニフェストは見つかりませんでした。将来の対応で安定したパッケージ URL を使えるよう、パッケージメタデータはここに公開されています。
エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。
local files
These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.
Config paths the tool may read or write during local use.
./.pinact.yaml./.github/pinact.yaml./.pinact.yml./.github/pinact.yml実行可能ファイル
| コマンド | 種類 | 公開範囲 | メモ |
|---|---|---|---|
pinact | cli | グローバル実行可能ファイル |
鮮度
これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。
https://github.com/suzuki-shunsuke/pinact
インストールメタデータ
| パッケージキー | brew:pinact |
|---|---|
| バージョン | 5.0.0 |
| パッケージマネージャ | Homebrew |
| パッケージマネージャページ | https://formulae.brew.sh/formula/pinact |
| ホームページ | https://github.com/suzuki-shunsuke/pinact |
| リポジトリ | https://github.com/suzuki-shunsuke/pinact |
| ライセンス | MIT |
| ソースアーカイブ | https://github.com/suzuki-shunsuke/pinact/archive/refs/tags/v4.1.1.tar.gz |
| 最終更新 | 2026-09-12T06:03:14Z |
| Pulse | updated |
| ビルド依存関係 | go |
| Bottle | 利用可能 (対象 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux) |
| Homebrew post-install | 未定義 |
| サービス | 宣言なし |
レジストリ情報
| Source Database | Homebrew formula API |
|---|---|
| Tap | homebrew/core |
| Full Name | pinact |
| Version Scheme | 0 |
| Revision | 0 |
| Head Version | HEAD |
| Bottle Stable Root URL | https://ghcr.io/v2/homebrew/core |
| Deprecated | no |
| Disabled | no |
| Keg Only | no |
| URL Keys |
|
ソースデータベース一致
一致は外部パッケージマネージャインデックスから取得され、ローカルの Automic Vault パッケージリンクとは分けて表示されます。
pinact
nix profile install nixpkgs#pinactpinact 4.1.1-1.1
CLI to edit GitHub Workflows and pin versions of Actions and Reusable Workflows
https://github.com/suzuki-shunsuke/pinact
sudo zypper install pinactpinact-bash-completion 4.1.1-1.1
Bash Completion for pinact
https://github.com/suzuki-shunsuke/pinact
sudo zypper install pinact-bash-completionpinact-fish-completion 4.1.1-1.1
Fish Completion for pinact
https://github.com/suzuki-shunsuke/pinact
sudo zypper install pinact-fish-completionpinact-zsh-completion 4.1.1-1.1
Zsh Completion for pinact
https://github.com/suzuki-shunsuke/pinact
sudo zypper install pinact-zsh-completionpinact
sudo port install pinactsuzuki-shunsuke.pinact
winget install --id suzuki-shunsuke.pinact -eソース経路
このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。
View the package source record on GitHub.