Earlier quoted context omitted.
The problem is actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 probably doesn’t do this same pinning, and the actions ecosystem is such an intertwined mess that any single compromised action can propagate to the rest
Well, it is a git commit hash of the action repo that contains the transpiled/bundled javascript. Like: https://github.com/actions/checkout/tree/11bd71901bbe5b1630c... So I'm pretty sure that for the same commit hash, I'll be executing the same content.
This article[0] gives a good overview of the challenges, and also has a link to a concrete attack where this was exploited.
[0]: https://nesbitt.io/2025/12/06/github-actions-package-manager...