Slide 18
Slide 18 text
Immutable Actions
Mutable References
Actions can be referenced in workflow by
Git tag, release name, branch name or
SHA. Tag in particular are mutable by
design.
Risk
Mutable references can become subject
to history overwrite attacks or changes to
the target of the Git tags
Looks like a
released version,
but is a Git tag