The lack of lockfiles is wild. Every other package manager figured this out years ago.

Has anyone been bitten by a breaking change from an action update mid-pipeline?

Mid-pipeline? No, but midday, oh yeah.