uses: ref, almost always the moving major tag pullfrog/pullfrog@v0. That ref pins less than it appears to.
How the action is versioned
The published action is a thin bootstrap. The code behind both of its steps, the agent and the post-run cleanup that saves rotated credentials, comes from npm at^<version>. The behavior you care about therefore tracks the latest release in the current version line.
The uses: ref fixes two things:
- The input and output contract, read from the action’s
action.yml. - The npm range the bootstrap resolves:
^<version>as of the pinned revision.
pullfrog/pullfrog@v0 tag tracks the latest v0.x release. The console writes this ref, and it is the one we recommend.
Pinning to a commit SHA
GitHub’s security hardening guide recommends pinning third-party actions to a full commit SHA, because tags can move. Dependabot, StepSecurity andpin-github-action do this for you and keep the version as a comment:
# v0 comment together:

