version-pinning

1 article
sort: new top best
clear filter
0 7/10

Comprehensive analysis of how various DevOps tools (GitHub Actions, Ansible Galaxy, Terraform, Helm) have organically developed package-manager characteristics with transitive dependency graphs, yet lack mature security controls like lockfiles, integrity verification, and immutable versioning that traditional package managers have implemented. Identifies systematic supply chain vulnerabilities across these ecosystems including mutable version tags, missing constraint solvers, and unpinnable transitive dependencies.

GitHub Actions Ansible Galaxy Terraform Helm npm Cargo Bundler resolvelib Palo Alto tj-actions/changed-files reviewdog/action-setup Mazer Argo CD Andrew Nesbitt NDC Oslo 2025
nesbitt.io · jandeboevrie · 6 days ago · details · hn