Semgrep has enabled organization-wide enforcement requiring GitHub Actions to be pinned to full 40-character commit SHAs, expanding a supply-chain hardening effort prompted by the compromise of the tj-actions/changed-files action. The rollout covered about 350 repositories and addressed more than simple tag replacement, including workflows that referenced branches and transitive dependencies introduced through composite actions and reusable workflows. GitHub’s control is designed to prevent mutable references from silently changing, and the effort aligned with broader guidance around immutable releases and action integrity.
The deployment used automation to find and remediate directly unpinned actions, while Renovate was used to keep pinned SHAs updated over time. Semgrep also worked through edge cases involving internal actions, reusable workflows, archived repositories, and abandoned third-party dependencies before moving from staged repository-level enforcement to an organization-wide policy. The result was a broad lock-down of GitHub Actions references intended to reduce the risk of future CI/CD supply-chain compromise.

Trace attribution and downstream blast radius.
6 events from the most recent confirmed update back to the earliest known activity.
In early 2025, attackers changed every tagged release of tj-actions/changed-files to point to a malicious commit. Repositories using the action by tag rather than a full 40-character commit SHA would execute malicious code when workflows ran.
After resolving remaining issues and cleaning up archived or inactive repositories, Semgrep enabled GitHub's full-length SHA-pinning requirement organization-wide. Renovate was used to keep pinned action references updated after enforcement was in place.
Semgrep first turned on SHA-pinning enforcement at the repository level and monitored for workflow failures. This staged rollout exposed issues such as branch-based references, transitively unpinned internal actions, a reusable-workflow detection gap, and a problematic SLSA GitHub Generator reference.
Semgrep removed pre-commit/action from about 10 repositories because the project was in maintenance mode and contained an unpinned reference to actions/cache. This was part of remediating transitively unpinned third-party actions.
The rollout initially found about 100 repositories that required pinning remediation. After archiving roughly 20 repositories, the active remediation set dropped to about 80.
Motivated by the tj-actions/changed-files incident, Semgrep launched a rollout to enforce GitHub's setting requiring GitHub Actions to be pinned to full-length commit SHAs across roughly 350 repositories. The effort included automation to detect direct tag usage, branch references, and transitively unpinned actions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
semgrep.dev
Open sourcedocs.github.com
Open sourcestepsecurity.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.