Skip to content

File tree

5 files changed

+27
-27
lines changed

5 files changed

+27
-27
lines changed

.github/workflows/daily-scan.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -44,7 +44,7 @@ jobs:
4444
less aws-opentelemetry-distro/requirements.txt
4545
4646
- name: Install java for dependency scan
47-
uses: actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 #v4.7.1
47+
uses: actions/setup-java@dded0888837ed1f317902acf8a20df0ad188d165 #v5.0.0
4848
with:
4949
java-version: 17
5050
distribution: 'temurin'

.github/workflows/post-release-version-bump.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ jobs:
2424
runs-on: ubuntu-latest
2525
steps:
2626
- name: Checkout main
27-
uses: actions/checkout@v2
27+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 #v5.0.0
2828
with:
2929
ref: main
3030
fetch-depth: 0
@@ -63,21 +63,21 @@ jobs:
6363
needs: check-version
6464
steps:
6565
- name: Configure AWS credentials for BOT secrets
66-
uses: aws-actions/configure-aws-credentials@v4
66+
uses: aws-actions/configure-aws-credentials@a03048d87541d1d9fcf2ecf528a4a65ba9bd7838 #v5.0.0
6767
with:
6868
role-to-assume: ${{ secrets.AWS_ROLE_ARN_SECRETS_MANAGER }}
6969
aws-region: ${{ env.AWS_DEFAULT_REGION }}
7070

7171
- name: Get Bot secrets
72-
uses: aws-actions/aws-secretsmanager-get-secrets@v1
72+
uses: aws-actions/aws-secretsmanager-get-secrets@a9a7eb4e2f2871d30dc5b892576fde60a2ecc802 #v2.0.10
7373
id: bot_secrets
7474
with:
7575
secret-ids: |
7676
BOT_TOKEN ,${{ secrets.BOT_TOKEN_SECRET_ARN }}
7777
parse-json-secrets: true
7878

7979
- name: Setup Git
80-
uses: actions/checkout@v2
80+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 #v5.0.0
8181
with:
8282
fetch-depth: 0
8383
token: ${{ env.BOT_TOKEN_GITHUB_RW_PATOKEN }}

.github/workflows/pre-release-prepare.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -25,21 +25,21 @@ jobs:
2525
runs-on: ubuntu-latest
2626
steps:
2727
- name: Configure AWS credentials for BOT secrets
28-
uses: aws-actions/configure-aws-credentials@v4
28+
uses: aws-actions/configure-aws-credentials@a03048d87541d1d9fcf2ecf528a4a65ba9bd7838 #v5.0.0
2929
with:
3030
role-to-assume: ${{ secrets.AWS_ROLE_ARN_SECRETS_MANAGER }}
3131
aws-region: ${{ env.AWS_DEFAULT_REGION }}
3232

3333
- name: Get Bot secrets
34-
uses: aws-actions/aws-secretsmanager-get-secrets@v1
34+
uses: aws-actions/aws-secretsmanager-get-secrets@a9a7eb4e2f2871d30dc5b892576fde60a2ecc802 #v2.0.10
3535
id: bot_secrets
3636
with:
3737
secret-ids: |
3838
BOT_TOKEN ,${{ secrets.BOT_TOKEN_SECRET_ARN }}
3939
parse-json-secrets: true
4040

4141
- name: Checkout main branch
42-
uses: actions/checkout@v3
42+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 #v5.0.0
4343
with:
4444
ref: 'main'
4545
token: ${{ env.BOT_TOKEN_GITHUB_RW_PATOKEN }}

.github/workflows/release-build.yml

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ jobs:
2626
runs-on: ubuntu-latest
2727
steps:
2828
- name: Checkout Repo @ SHA - ${{ github.sha }}
29-
uses: actions/checkout@v4
29+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 #v5.0.0
3030

3131
- name: Check main build status
3232
env:
@@ -61,13 +61,13 @@ jobs:
6161
# https://github.com/aws-observability/aws-otel-java-instrumentation/tree/93870a550ac30988fbdd5d3bf1e8f9f1b37916f5/smoke-tests
6262

6363
- name: Configure AWS credentials for PyPI secrets
64-
uses: aws-actions/configure-aws-credentials@v4
64+
uses: aws-actions/configure-aws-credentials@a03048d87541d1d9fcf2ecf528a4a65ba9bd7838 #v5.0.0
6565
with:
6666
role-to-assume: ${{ secrets.AWS_ROLE_ARN_SECRETS_MANAGER }}
6767
aws-region: ${{ env.AWS_DEFAULT_REGION }}
6868

6969
- name: Get PyPI secrets
70-
uses: aws-actions/aws-secretsmanager-get-secrets@v1
70+
uses: aws-actions/aws-secretsmanager-get-secrets@a9a7eb4e2f2871d30dc5b892576fde60a2ecc802 #v2.0.10
7171
id: pypi_secrets
7272
with:
7373
secret-ids: |
@@ -76,24 +76,24 @@ jobs:
7676
parse-json-secrets: true
7777

7878
- name: Configure AWS credentials for private ECR
79-
uses: aws-actions/configure-aws-credentials@v4
79+
uses: aws-actions/configure-aws-credentials@a03048d87541d1d9fcf2ecf528a4a65ba9bd7838 #v5.0.0
8080
with:
8181
role-to-assume: ${{ secrets.AWS_ROLE_ARN_ECR_RELEASE }}
8282
aws-region: ${{ env.AWS_PRIVATE_ECR_REGION }}
8383

8484
- name: Log in to AWS private ECR
85-
uses: docker/login-action@v3
85+
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 #v3.5.0
8686
with:
8787
registry: ${{ env.RELEASE_PRIVATE_REGISTRY }}
8888

8989
- name: Configure AWS credentials for public ECR
90-
uses: aws-actions/configure-aws-credentials@v4
90+
uses: aws-actions/configure-aws-credentials@a03048d87541d1d9fcf2ecf528a4a65ba9bd7838 #v5.0.0
9191
with:
9292
role-to-assume: ${{ secrets.AWS_ROLE_ARN_ECR_RELEASE }}
9393
aws-region: ${{ env.AWS_PUBLIC_ECR_REGION }}
9494

9595
- name: Log in to AWS public ECR
96-
uses: docker/login-action@v3
96+
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 #v3.5.0
9797
with:
9898
registry: public.ecr.aws
9999

@@ -119,7 +119,7 @@ jobs:
119119
120120
# Publish to public ECR
121121
- name: Build and push public ECR image
122-
uses: docker/build-push-action@v5
122+
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 #v6.18.0
123123
with:
124124
push: true
125125
context: .
@@ -130,7 +130,7 @@ jobs:
130130
131131
# Publish to private ECR
132132
- name: Build and push private ECR image
133-
uses: docker/build-push-action@v5
133+
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 #v6.18.0
134134
with:
135135
push: true
136136
context: .

.github/workflows/release-lambda.yml

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -40,8 +40,8 @@ jobs:
4040
echo ${MATRIX}
4141
echo "aws_regions_json=${MATRIX}" >> $GITHUB_OUTPUT
4242
- name: Checkout Repo @ SHA - ${{ github.sha }}
43-
uses: actions/checkout@v4
44-
- uses: actions/setup-python@v5
43+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 #v5.0.0
44+
- uses: actions/setup-python@e797f83bcb11b83ae66e0230d6156d7c80228e7c #v6.0.0
4545
with:
4646
python-version: '3.x'
4747
- name: Build layers
@@ -51,7 +51,7 @@ jobs:
5151
pip install tox
5252
tox
5353
- name: upload layer
54-
uses: actions/upload-artifact@v4
54+
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 #v4.6.2
5555
with:
5656
name: layer.zip
5757
path: lambda-layer/src/build/aws-opentelemetry-python-layer.zip
@@ -83,7 +83,7 @@ jobs:
8383
fi
8484
SECRET_KEY=${SECRET_KEY//-/_}
8585
echo "SECRET_KEY=${SECRET_KEY}" >> $GITHUB_ENV
86-
- uses: aws-actions/configure-aws-credentials@v4.0.2
86+
- uses: aws-actions/configure-aws-credentials@a03048d87541d1d9fcf2ecf528a4a65ba9bd7838 #v5.0.0
8787
with:
8888
role-to-assume: ${{ secrets[env.SECRET_KEY] }}
8989
role-duration-seconds: 1200
@@ -92,7 +92,7 @@ jobs:
9292
run: |
9393
echo BUCKET_NAME=python-lambda-layer-${{ github.run_id }}-${{ matrix.aws_region }} | tee --append $GITHUB_ENV
9494
- name: download layer.zip
95-
uses: actions/download-artifact@v4
95+
uses: actions/download-artifact@634f93cb2916e3fdff6788551b99b062d0335ce0 #v5.0.0
9696
with:
9797
name: layer.zip
9898
- name: publish
@@ -130,7 +130,7 @@ jobs:
130130
--action lambda:GetLayerVersion
131131
- name: upload layer arn artifact
132132
if: ${{ success() }}
133-
uses: actions/upload-artifact@v4
133+
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 #v4.6.2
134134
with:
135135
name: ${{ env.LAYER_NAME }}-${{ matrix.aws_region }}
136136
path: ${{ env.LAYER_NAME }}/${{ matrix.aws_region }}
@@ -143,10 +143,10 @@ jobs:
143143
needs: publish-prod
144144
steps:
145145
- name: Checkout Repo @ SHA - ${{ github.sha }}
146-
uses: actions/checkout@v4
147-
- uses: hashicorp/setup-terraform@v2
146+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 #v5.0.0
147+
- uses: hashicorp/setup-terraform@b9cd54a3c349d3f38e8881555d616ced269862dd #v3.1.2
148148
- name: download layerARNs
149-
uses: actions/download-artifact@v4
149+
uses: actions/download-artifact@634f93cb2916e3fdff6788551b99b062d0335ce0 #v5.0.0
150150
with:
151151
pattern: ${{ env.LAYER_NAME }}-*
152152
path: ${{ env.LAYER_NAME }}
@@ -195,7 +195,7 @@ jobs:
195195
echo "}" >> ../layer_cdk
196196
cat ../layer_cdk
197197
- name: download layer.zip
198-
uses: actions/download-artifact@v4
198+
uses: actions/download-artifact@634f93cb2916e3fdff6788551b99b062d0335ce0 #v5.0.0
199199
with:
200200
name: layer.zip
201201
- name: Rename layer file

0 commit comments

Comments
 (0)