For the secure supply chain folks, the ability to make a GitHub release and everything associated with it as immutable is in public preview.

github.blog/changelog/2025-08-

I hope every GitHub Action picks this up so we can use version tags safely instead of having to rely on hashes and a comment for what a hash corresponds to to choose the version of the action to use.

0

If you have a fediverse account, you can quote this note from your own instance. Search https://mastodon.social/users/brettcannon/statuses/115097237876998882 on your instance and quote it. (Note that quoting is not supported in Mastodon.)