Tags lie. Digests don’t.
Turn any dependency into an immutable, pinned reference with a single lookup.
Paste package.json, Dockerfile, workflow YAML, requirements files, or a raw HTTPS file URL.
package.json