Want to speak? Submit your talk and join our line up of speakers!
Community
Community
Overview
The story and values that drive us
Ambassadors
Become a Platform Engineering Ambassador
Events
Check out upcoming events near you
Reports
Check out the #1 source of industry stats
Jobs
Find your next  platform engineering role
Join Community
Join and contribute
Vendor opportunities
Certifications
Introduction to Platform Engineering
Platform Engineering Certified Practitioner
Platform Engineering Certified Architect
Agent infrastructure for Platform Engineers
new
Agentic Development Platforms
new
...and many more. Check out Platform Engineering University
Get Certified
For organizations
FOR ENTERPRISE TEAMS
Training & advisory
Home
Services
Results
Resources
FOR Partners
Service Provider
Training Reseller
Certified Provider Directory
BlogLandscape
Get certified
Join community
Join community
Get certified
All events
GitHub Actions security beyond SHA pinning
Virtual
In-person
GitHub Actions security beyond SHA pinning
Oct 20, 2026
7:00 pm
CEST
CEST
-
45 minutes
Agentic development is pushing more code through CI than ever, and platform teams are the ones calling for SHA pinning across their organizations. GitHub supports it as an org-level policy, hardening guides recommend it, and after the tj-actions and the Trivy compromise, few teams argue that it isn’t a best practice. But SHA pinning solves a narrower problem than most teams think. Pinning guarantees that the bytes don't change, not who wrote them, or whether they were part of the project you think you're running. Since any fork commit is reachable from the upstream repository, a pinned SHA can be an attacker's commit, and it'll look correct in your review, audit log, and policy scanner. Even a Docker-based action, when pinned to a SHA, still builds its image at runtime.
Register
Watch recording
Speaker
Erika Heidi
Staff Developer Relations Engineer @ Chainguard
Speaker
Speaker
Speaker

In this webinar, we’ll draw the line between immutability and provenance, evaluate GitHub's 2026 dependency-locking roadmap, and weigh the alternative approaches to trust.

We'll discuss:

  • What org-level pin enforcement actually verifies
  • How impostors commit work, and why GitHub's repo network makes them possible
  • What GitHub's Actions roadmap addresses, and what it doesn’t
  • What else is available to close the gap, including a curated catalog

​

This event is exclusive. Reserve your spot now.
Register now
Watch recording
Join our Slack

Join the conversation to stay on top of trends and opportunities in the platform engineering community.

Join Slack
Sitemap
HomeAboutAmbassadorsCertificationsEventsJobs
Resources
BlogPlatformConCertified provider directoryWhat is platform engineering?Platform toolingVendor opportunities
Join US
Youtube
LinkedIn
Platform Weekly
Twitter
House of Kube
Weave Intelligence

Subscribe to Platform Weekly

Platform engineering deep dives and DevOps trends, delivered to your inbox crunchy, every week.

© 2026 Platform Engineering. All rights reserved.
Privacy Policy
Privacy PolicyTerms of ServiceCookies Settings
Supported by
Register now