diff --git a/.github/workflows/checks.yml b/.github/workflows/checks.yml index ae838466..0bdfaacf 100644 --- a/.github/workflows/checks.yml +++ b/.github/workflows/checks.yml @@ -68,6 +68,6 @@ jobs: with: persist-credentials: false - - uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0 + - uses: actions/setup-node@2028fbc5c25fe9cf00d9f06a71cc4710d4507903 # v6.0.0 - run: npx prettier --prose-wrap always --check . diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 985b1134..e46a794c 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -67,7 +67,7 @@ jobs: with: persist-credentials: false - - uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0 + - uses: actions/setup-node@2028fbc5c25fe9cf00d9f06a71cc4710d4507903 # v6.0.0 - run: npx prettier --prose-wrap always --check . diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 9afa486e..475482f5 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -59,7 +59,7 @@ jobs: # Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF # format to the repository Actions tab. - name: 'Upload artifact' - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5.0.0 with: name: SARIF file path: results.sarif @@ -68,6 +68,6 @@ jobs: # Upload the results to GitHub's code scanning dashboard (optional). # Commenting out will disable upload of results to your repo's Code Scanning dashboard - name: 'Upload to code-scanning' - uses: github/codeql-action/upload-sarif@64d10c13136e1c5bce3e5fbde8d4906eeaafc885 # v3.30.6 + uses: github/codeql-action/upload-sarif@0499de31b99561a6d14a36a5f662c2a54f91beee # v4.31.2 with: sarif_file: results.sarif diff --git a/.github/workflows/semantic.yml b/.github/workflows/semantic.yml index 0f5708c7..97c63eca 100644 --- a/.github/workflows/semantic.yml +++ b/.github/workflows/semantic.yml @@ -50,7 +50,7 @@ jobs: - run: python3 generators/generate-debian-versions.py - run: git status - run: stat debian-db.zip - - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + - uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5.0.0 with: name: generated-debian-versions path: generators/testdata/debian-versions-generated.txt @@ -83,7 +83,7 @@ jobs: - run: python3 generators/generate-redhat-versions.py - run: git status - run: stat redhat-db.zip - - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + - uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5.0.0 with: name: generated-redhat-versions path: generators/testdata/redhat-versions-generated.txt @@ -107,7 +107,7 @@ jobs: extensions: zip - run: php generators/generate-packagist-versions.php - run: git status - - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + - uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5.0.0 with: name: generated-packagist-versions path: generators/testdata/packagist-versions-generated.txt @@ -127,7 +127,7 @@ jobs: run: pip install packaging==21.3 - run: python3 generators/generate-pypi-versions.py - run: git status - - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + - uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5.0.0 with: name: generated-pypi-versions path: generators/testdata/pypi-versions-generated.txt @@ -147,7 +147,7 @@ jobs: run: gem install rubyzip - run: ruby generators/generate-rubygems-versions.rb - run: git status - - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + - uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5.0.0 with: name: generated-rubygems-versions path: generators/testdata/rubygems-versions-generated.txt @@ -173,7 +173,7 @@ jobs: -o generators/lib/maven-artifact-3.8.5.jar - run: java -cp 'generators/lib/*' generators/GenerateMavenVersions.java - run: git status - - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + - uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5.0.0 with: name: generated-maven-versions path: generators/testdata/maven-versions-generated.txt @@ -191,7 +191,7 @@ jobs: r-version: '3.5.3' - run: Rscript generators/generate-cran-versions.R - run: git status - - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + - uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5.0.0 with: name: generated-cran-versions path: generators/testdata/cran-versions-generated.txt @@ -218,7 +218,7 @@ jobs: go-version-file: .go-version cache: true - - uses: actions/download-artifact@634f93cb2916e3fdff6788551b99b062d0335ce0 # v5.0.0 + - uses: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53 # v6.0.0 with: pattern: generated-*-versions path: generators/testdata/