On the .md file, it is suggested to add the Claude action without verification of the SHA:
- uses: anthropics/claude-code-security-review@main
This is not pinned to a full commit SHA, which makes it mutable and exposes downstream users to supply chain risk if main is changed or compromised.
This is a small thing, but as the attacks increase each day and more and more automations are implemented, small things like this might make a difference:
- uses: anthropics/claude-code-security-review@full-40-char-sha
On the .md file, it is suggested to add the Claude action without verification of the SHA:
This is not pinned to a full commit SHA, which makes it mutable and exposes downstream users to supply chain risk if main is changed or compromised.
This is a small thing, but as the attacks increase each day and more and more automations are implemented, small things like this might make a difference: