Pin every third-party action in .github/workflows/ to a full commit SHA with a trailing version comment, and bump to the latest stable release. Defends against tag-rewrite supply-chain attacks while keeping versions legible.
Allows manually triggering spec generation from the Actions tab with version selection and optional push to appwrite/specs repo.