pkg.soopen package index

npm / 排名 2342

使用 npm 安装 pin-github-action

查看 pin-github-action 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

安装

其他安装命令

便携式和语言管理器

npm已验证 · 100%
npm install -g pin-github-action

local npm package metadata

概览

软件包摘要

Pin your GitHub Actions to specific versions automatically!

命令和别名

  • pin-github-action

安全态势

尚未找到受保护工具覆盖

没有找到 pin-github-action 的匹配本地密钥处理 manifest。软件包元数据仍在此发布,以便未来覆盖拥有稳定的软件包 URL。

安装行为

  • 软件包元数据中未记录 npm postinstall 脚本。
  • 未记录 Homebrew bottle 元数据。
  • 安装时包含 7 个运行时依赖。
  • 构建元数据列出 6 个构建依赖。

建议审查

在无人值守的代理使用前,请检查该工具是否读取明文凭据、写入远程状态、发布制品或调用插件。

可执行文件

已安装的可执行文件

命令类型暴露范围备注
pin-github-actioncli全局可执行文件

新鲜度

版本和新鲜度

这些信号区分页生成时间、软件包管理器活动和上游发布比较。只有存在证据 URL 和可比较版本时,才会提示版本落后。

页面生成时间2026-08-04
管理器版本3.5.1
管理器更新时间2026-07-06
本地数据OK
上游not checked
检测到的最新版本未检测到

https://github.com/mheap/pin-github-action

安装元数据

软件包元数据

软件包键npm:pin-github-action
版本3.5.1
软件包管理器npm
软件包管理器页面https://www.npmjs.com/package/pin-github-action
主页https://github.com/mheap/pin-github-action#readme
仓库https://github.com/mheap/pin-github-action
上游文档https://github.com/mheap/pin-github-action#readme
许可证MIT
源码归档https://registry.npmjs.org/pin-github-action/-/pin-github-action-3.5.1.tgz
问题跟踪器https://github.com/mheap/pin-github-action/issues
最后更新2026-07-06T17:28:10.617Z
发布时间2026-07-06T17:28:10.617Z
Pulseupdated
依赖@octokit/rest, commander, debug, escape-string-regexp, fast-glob, matcher, yaml
构建依赖cross-env, eslint, eslint-plugin-prettier, jest, nock, prettier
Bottle未记录
npm postinstall未定义
服务未声明
关键词github actions, github, security

注册表事实

源数据库详情

Source Databasenpm registry
Dist Tags
Version Count34
Maintainers
  • mheap
AuthorMichael Heap
Publishermheap
Integritysha512-scqqzMseLA3laGJtptuDhlxzb2l4zvHS6HBh2TnHPbdd3f51zcAeNoMmKhHx2Hi7XPoHlj/ArAUEhMtAEdyoBg==
Shasuma2567275acf2a471f50171a4667b0efa315574a5
Unpacked Size59,828
File Count0
Created At2020-01-14T15:53:22.775Z
Latest Published At2026-07-06T17:28:10.617Z
Modified At2026-07-06T17:28:10.742Z

来源线索

由仓库数据生成

此页面由 av-webscripts/generate-pkg-sqlite.py 生成的私有软件包 SQLite 工件提供。

使用的来源

  • cross-ecosystem install command graph
  • package relationship graph
  • package version freshness
  • package-page enrichment
  • pkg.so package database
  • pkgdb category and tag curation