Pipeline dependencies are code-execution dependencies

Every action, plugin or step you pull into a pipeline runs code with the pipeline's access.

They are usually chosen casually, referenced by a moving tag, and updated silently by their author. That is a third party executing inside your build with your credentials. Pinning them to a specific commit rather than a tag is a small change that closes a large gap.

More on CI/CD security