> ## Documentation Index > Fetch the complete documentation index at: https://docs.pullfrog.com/llms.txt > Use this file to discover all available pages before exploring further. # Versions & pinning > What the action reference in your workflow pins, and how to pin it to a commit SHA. Your workflow references the action with a `uses:` ref, almost always the moving major tag `pullfrog/pullfrog@v0`. That ref pins less than it appears to. ## How the action is versioned The published action is a thin bootstrap. The code behind both of its steps, the agent and the post-run cleanup that saves rotated credentials, comes from npm at `^`. The behavior you care about therefore tracks the latest release in the current version line. The `uses:` ref fixes two things: * The input and output contract, read from the action's `action.yml`. * The npm range the bootstrap resolves: `^` as of the pinned revision. The `pullfrog/pullfrog@v0` tag tracks the latest `v0.x` release. The console writes this ref, and it is the one we recommend. ## Pinning to a commit SHA GitHub's [security hardening guide](https://docs.github.com/en/actions/security-for-github-actions/security-guides/security-hardening-for-github-actions) recommends pinning third-party actions to a full commit SHA, because tags can move. Dependabot, [StepSecurity](https://www.stepsecurity.io/) and `pin-github-action` do this for you and keep the version as a comment: ```yaml theme={null} uses: pullfrog/pullfrog@abc123… # v0 ``` A pinned SHA takes both steps from npm the same way the tag does, so the agent and the cleanup step still receive patch releases. Updating the pin is what picks up a new minor version. Dependabot bumps the SHA and the `# v0` comment together: ```yaml theme={null} # .github/dependabot.yml version: 2 updates: - package-ecosystem: github-actions directory: / schedule: interval: weekly ``` ## Choosing a ref | You want | Use | | - | - | | The simplest setup that stays current | `pullfrog/pullfrog@v0` | | SHA pinning for a security policy | A commit SHA, with Dependabot to pick up new minor versions | This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.