Semgrep describes enforcing SHA-pinned GitHub Actions across about 350 repositories and what the setting actually requires
- Sources: primary, discussion
- Summary: The post names the three failure buckets that break CI when the setting goes on: direct tags, direct branches and transitively unpinned actions. It records that composite actions must be pinned while reusable workflows need not be.
- Why it matters: Teams turning on org-wide SHA pinning get the concrete set of failures to fix before CI breaks.