Actions Up
I wanted to keep GitHub Actions up to date and protect against supply chain attacks at the same time. Checking every action by hand takes a long time, so I decided to automate it.
Actions Up finds every action in the .github directory, checks for new versions, and lets you choose what to update. It pins updated actions to a commit SHA and keeps the version number in a comment.
Before:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4After:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0Actions run third-party code in CI, often with access to secrets. A tag like v4 can be moved to a different commit, and the next run will execute different code. That can’t happen with a SHA.
By default, Actions Up also doesn’t offer releases that are less than a day old. This protects against attacks through freshly published versions. You can change the threshold with the --min-age flag.
How to start using it?
Run Actions Up in the root of your repository:
npx actions-upTo just see the updates without changing anything, add the --dry-run flag.