JackSlateur 12 hours ago

Long story short: yes, you can pin your github action (and you should)

No, you shan't execute random code from internet (that fact that you always execute the same random code is not important)

Github actions is fine in this regards;