From faf82cb92e2a31de3f8c40315455f9d442de35a9 Mon Sep 17 00:00:00 2001 From: Zanie Blue Date: Sat, 15 Mar 2025 13:31:58 -0500 Subject: [PATCH] Pin third-party GitHub Actions --- .github/workflows/linux.yml | 4 ++-- .github/workflows/release.yml | 2 +- .github/workflows/windows.yml | 2 +- 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/linux.yml b/.github/workflows/linux.yml index e7281574..0a567f35 100644 --- a/.github/workflows/linux.yml +++ b/.github/workflows/linux.yml @@ -76,10 +76,10 @@ jobs: python-version: '3.11' - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v3 + uses: docker/setup-buildx-action@b5ca514318bd6ebac0fb2aedd5d36ec1b5c232a2 # v3 - name: Login to GitHub Container Registry - uses: docker/login-action@v3 + uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3 with: registry: ghcr.io username: ${{ github.actor }} diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 7993fe5c..ce803392 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -35,7 +35,7 @@ jobs: with: submodules: recursive - - uses: extractions/setup-just@v2 + - uses: extractions/setup-just@dd310ad5a97d8e7b41793f8ef055398d51ad4de6 # v2 # Perform a release in dry-run mode. - run: just release-dry-run ${{ secrets.GITHUB_TOKEN }} ${{ github.event.inputs.sha }} ${{ github.event.inputs.tag }} diff --git a/.github/workflows/windows.yml b/.github/workflows/windows.yml index 6065b439..cd2bef55 100644 --- a/.github/workflows/windows.yml +++ b/.github/workflows/windows.yml @@ -103,7 +103,7 @@ jobs: fetch-depth: 0 - name: Install Cygwin Environment - uses: cygwin/cygwin-install-action@49f298a7ebb00d4b3ddf58000c3e78eff5fbd6b9 + uses: cygwin/cygwin-install-action@49f298a7ebb00d4b3ddf58000c3e78eff5fbd6b9 # v2 with: packages: autoconf automake libtool