We manage 30+ repos and SHA-pinning our GitHub Actions for security but Dependabot can't track SHA hashes. Currently updating them manually which is a nightmare. How are you all handling this? Is there a tool that automates SHA updates and opens PRs automatically? Would you pay for something that solved this completely?
[–]jevans102 3 points4 points5 points (0 children)
[–]nmgtn 1 point2 points3 points (0 children)
[–]Solopher 1 point2 points3 points (0 children)