Skip to main content
Your workflow references the action with a uses: ref, almost always the moving major tag pullfrog/pullfrog@v0. That ref pins less than it appears to.

How the action is versioned

The published action is a thin bootstrap. The code behind both of its steps, the agent and the post-run cleanup that saves rotated credentials, comes from npm at ^<version>. The behavior you care about therefore tracks the latest release in the current version line. The uses: ref fixes two things:
  • The input and output contract, read from the action’s action.yml.
  • The npm range the bootstrap resolves: ^<version> as of the pinned revision.
The pullfrog/pullfrog@v0 tag tracks the latest v0.x release. The console writes this ref, and it is the one we recommend.

Pinning to a commit SHA

GitHub’s security hardening guide recommends pinning third-party actions to a full commit SHA, because tags can move. Dependabot, StepSecurity and pin-github-action do this for you and keep the version as a comment:
A pinned SHA takes both steps from npm the same way the tag does, so the agent and the cleanup step still receive patch releases. Updating the pin is what picks up a new minor version. Dependabot bumps the SHA and the # v0 comment together:

Choosing a ref