Skip to content

Commit 2a091f8

Browse files
authored
Merge pull request #20 from The-Adimension/ci/pin-actions-to-sha
ci: pin all GitHub Actions to immutable commit SHAs
2 parents 323a8a3 + 0df6501 commit 2a091f8

File tree

5 files changed

+14
-14
lines changed

5 files changed

+14
-14
lines changed

.github/workflows/bandit.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -34,9 +34,9 @@ jobs:
3434
contents: read
3535
security-events: write
3636
steps:
37-
- uses: actions/checkout@v4
37+
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
3838

39-
- uses: actions/setup-python@v5
39+
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5
4040
with:
4141
python-version: '3.12'
4242

@@ -51,14 +51,14 @@ jobs:
5151

5252
- name: Upload SARIF
5353
if: always()
54-
uses: github/codeql-action/upload-sarif@v3
54+
uses: github/codeql-action/upload-sarif@820e3160e279568db735cee8ed8f8e77a6da7818 # v3
5555
with:
5656
sarif_file: bandit.sarif
5757
category: bandit
5858

5959
- name: Upload JSON report
6060
if: always()
61-
uses: actions/upload-artifact@v4
61+
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
6262
with:
6363
name: bandit-report
6464
path: bandit-report.json

.github/workflows/codeql-analysis.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -42,17 +42,17 @@ jobs:
4242

4343
steps:
4444
- name: Checkout repository
45-
uses: actions/checkout@v4
45+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
4646

4747
- name: Initialize CodeQL
48-
uses: github/codeql-action/init@v3
48+
uses: github/codeql-action/init@820e3160e279568db735cee8ed8f8e77a6da7818 # v3
4949
with:
5050
languages: ${{ matrix.language }}
5151

5252
- name: Autobuild
53-
uses: github/codeql-action/autobuild@v3
53+
uses: github/codeql-action/autobuild@820e3160e279568db735cee8ed8f8e77a6da7818 # v3
5454

5555
- name: Perform CodeQL Analysis
56-
uses: github/codeql-action/analyze@v3
56+
uses: github/codeql-action/analyze@820e3160e279568db735cee8ed8f8e77a6da7818 # v3
5757
with:
5858
category: "/language:${{matrix.language}}"

.github/workflows/pip-audit.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -24,10 +24,10 @@ jobs:
2424

2525
steps:
2626
- name: Checkout code
27-
uses: actions/checkout@v4
27+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
2828

2929
- name: Set up Python
30-
uses: actions/setup-python@v5
30+
uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5
3131
with:
3232
python-version: "3.12"
3333

.github/workflows/scorecard.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ jobs:
2727

2828
steps:
2929
- name: Checkout code
30-
uses: actions/checkout@v4
30+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
3131
with:
3232
persist-credentials: false
3333

@@ -39,7 +39,7 @@ jobs:
3939
publish_results: true
4040

4141
- name: Upload SARIF to Code Scanning
42-
uses: github/codeql-action/upload-sarif@v3
42+
uses: github/codeql-action/upload-sarif@820e3160e279568db735cee8ed8f8e77a6da7818 # v3
4343
if: always()
4444
with:
4545
sarif_file: results.sarif

.github/workflows/semgrep.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -38,13 +38,13 @@ jobs:
3838
contents: read
3939
security-events: write
4040
steps:
41-
- uses: actions/checkout@v4
41+
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
4242

4343
- name: Semgrep scan
4444
run: semgrep scan --config=auto --sarif -o semgrep.sarif || true
4545

4646
- name: Upload SARIF
4747
if: always()
48-
uses: github/codeql-action/upload-sarif@v3
48+
uses: github/codeql-action/upload-sarif@820e3160e279568db735cee8ed8f8e77a6da7818 # v3
4949
with:
5050
sarif_file: semgrep.sarif

0 commit comments

Comments
 (0)