# Pinner

> Use this tool when you need to enhance security and reproducibility in your workflows by pinning dependencies to specific versions. Pinner resolves GitHub references and Docker image tags to unique identifiers, preventing potential supply chain attacks through dependency substitution. It provides precise version control for GitHub Actions workflows and Dockerfiles, ensuring immutably referenced external dependencies.

Canonical page: https://skillsregistry.net/skills/safedep-pinner  
JSON: https://api.skillsregistry.net/v1/skills/safedep-pinner

## Description

Pinner-MCP is a Model Context Protocol server that helps pin dependencies to specific versions for enhanced security and reproducibility. It provides tools to resolve GitHub references to commit SHAs and Docker image tags to digests, enabling precise version pinning in GitHub Actions workflows and Dockerfiles. Built by SafeDep, this implementation focuses on supply chain security by ensuring that external dependencies are immutably referenced, preventing potential supply chain attacks through dependency substitution.

## Trust

- **Trust score (0–1):** 0.99
- **Verification tier:** verified
- **Last scanned:** 2026-09-28

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** version-control
- **Updated:** 2026-09-28

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/safedep-pinner)
- **Repository:** <https://github.com/safedep/pinner-mcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "safedep-pinner"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/safedep-pinner` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/safedep-pinner/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
