github-actions-ensure-sha-pinned-actions
github-actions-ensure-sha-pinned-actions copied to clipboard
[Improvement] Check dependencies recursively
Hi, Thank you for this github action, it is very useful.
At the moment, if I'm not mistaken, it only check the .github folder, but if we have some actions that use another action, which use an untrusted action, then it will not be checked, so it will not fail. What do you think about having something recursive?
Best, Michael
Possibly related:
- https://github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/issues/117