Pinned action references
A reference such as actions/checkout@v4 can point at different code tomorrow. A full commit SHA cannot.
Proofline reads each external uses: reference in the reviewed commit. A deterministic check reports every mutable reference, and the result can block a merge gate. The check reports an expression it cannot resolve as unknown, so it never counts as pinned.
Deployment workflow changes
A change to a workflow file brings the deployment workflow risk domain into the review. The reviewer asks whether build and deployment steps still run in the right order and fail the right way.
For example, it asks whether a test step that moved after the deploy job still guards the deploy. It weighs the change against the deployments and release artifacts your workflows have recorded.
What Proofline reads from GitHub Actions
Proofline reads workflow runs, deployments, and release artifacts through the Proofline GitHub App. It uses short-lived installation tokens and stores no GitHub token.
To hold a deployment until its review completes, enable a deployment gate and add Proofline as a deployment protection rule.
Questions
Why pin GitHub Actions to a commit SHA?
A full commit SHA always names the same code, so the workflow runs what you reviewed. A tag or branch can move to new code without any change in your repository.
Does Proofline check local actions for pinning?
No. The pinning check covers external action references. Local actions in your own repository change through your own pull requests.
Can Proofline block a deployment from GitHub Actions?
Yes, if you enable a deployment gate. GitHub Actions then waits for Proofline through a deployment protection rule.