Explain the key differences between composite actions, Docker container actions, and JavaScript actions in GitHub Actions. When would you choose each type, and how does action versioning (@v1, @v1.2, @sha) affect consumers?
#Reveal answer guidance
JavaScript actions run directly on the runner (~2-5s startup), ideal for CI/CD logic and API calls. Docker container actions run in a container (~10-30s startup for image pull), providing environment isolation for tools like Terraform or gcc. Composite actions combine multiple steps in YAML with no packaging, ideal for reusing step patterns. Versioning: @v1 points to latest v1 (mutates), @v1.2 is a specific minor (safer), @<sha> pins to exact commit (most secure). OpenSSF Scorecard recommends SHA pinning with automated updates via renovate/dependabot. Major version branches should move with backwards-compatible releases.