Securing CI/CD for an open source project: Locking down dependencies
…Upstream actions regularly fix bugs and ship security features. Forks add friction to picking those up. Renovate complexity. Our update pipeline would have to track upstream releases, open PRs against each fork…