9b11d73273
Every action in ci.yml and release.yml was pinned to a movable tag (actions/checkout@v4, dtolnay/rust-toolchain@stable, ...). A compromised upstream tag would run with access to the crates.io / PyPI / npm publish tokens. Pin every `uses:` to the full 40-character commit SHA the referenced ref currently resolves to, with the human-readable version kept as a trailing comment so Dependabot can still bump them: actions/checkout v4.3.1 actions/setup-python v5.6.0 actions/setup-node v4.4.0 actions/upload-artifact v4.6.2 actions/download-artifact v4.3.0 dtolnay/rust-toolchain stable branch @ 2026-03-27 Swatinem/rust-cache v2 jetli/wasm-pack-action v0.4.0 PyO3/maturin-action v1.51.0 softprops/action-gh-release v2.6.2 SHAs were resolved against the GitHub API. The github-actions Dependabot ecosystem that keeps these pins current is added with E3.