2424 # Get GitHub token via the CT SDKs App
2525 - name : Generate GitHub token (via CT SDKs App)
2626 id : generate_github_token
27- uses : actions/create-github-app-token@a0de6af83968303c8c955486bf9739a57d23c7f1 # v1
27+ uses : actions/create-github-app-token@c1a285145b9d317df6ced56c09f525b5c2b6f755 # v1
2828 with :
2929 app-id : ${{ secrets.CT_SDKS_APP_ID }}
3030 private-key : ${{ secrets.CT_SDKS_APP_PEM }}
@@ -38,16 +38,16 @@ jobs:
3838 echo "email=${GH_APP_USER}+ct-sdks[bot]@users.noreply.github.com" >> "$GITHUB_OUTPUT"
3939
4040 - name : Checkout
41- uses : actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4
41+ uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
4242 with :
4343 # Pass a personal access token (using our CT SDKs App) to be able to trigger other workflows
4444 # https://help.github.com/en/actions/reference/events-that-trigger-workflows#triggering-new-workflows-using-a-personal-access-token
4545 # https://github.community/t/action-does-not-trigger-another-on-push-tag-action/17148/8
4646 token : ${{ steps.generate_github_token.outputs.token }}
47- - uses : gradle/wrapper-validation-action@216d1ad2b3710bf005dc39237337b9673fd8fcd5 # v3.3.2
47+ - uses : gradle/wrapper-validation-action@f9c9c575b8b21b6485636a91ffecd10e558c62f6 # v3.5.0
4848
4949 - name : Setup Java
50- uses : actions/setup-java@99b8673ff64fbf99d8d325f52d9a5bdedb8483e9 # v4
50+ uses : actions/setup-java@7a6d8a8234af8eb26422e24e3006232cccaa061b # v4
5151 with :
5252 distribution : ' temurin'
5353 java-version : ' 17'
@@ -111,6 +111,7 @@ jobs:
111111 run : git push origin
112112
113113 - name : Run integration tests for PR
114+ # ignore renovate branches as they are retriggered with every new commit to main branch
114115 if : (github.event_name == 'pull_request' && !startsWith(github.head_ref, 'renovate/')) || github.event_name == 'merge_group'
115116 run : ./gradlew clean build publishMavenPublicationToMavenLocal runMainMethodThreadLeakTest runMainMethodMemoryLeakTest writeVersionToExamples
116117 env :
@@ -139,7 +140,7 @@ jobs:
139140 run : ./gradlew codeCoverageReport
140141
141142 - name : Send code coverage report to Codecov.io
142- uses : codecov/codecov-action@125fc84a9a348dbcf27191600683ec096ec9021c # v4.4.1
143+ uses : codecov/codecov-action@b9fd7d16f6d7d1b5d2bec1a2887e65ceed900238 # v4.6.0
143144 with :
144145 token : ${{ secrets.CODECOV_TOKEN }}
145146 docs :
@@ -151,20 +152,20 @@ jobs:
151152 # Get GitHub token via the CT SDKs App
152153 - name : Generate GitHub token (via CT SDKs App)
153154 id : generate_github_token
154- uses : actions/create-github-app-token@a0de6af83968303c8c955486bf9739a57d23c7f1 # v1
155+ uses : actions/create-github-app-token@c1a285145b9d317df6ced56c09f525b5c2b6f755 # v1
155156 with :
156157 app-id : ${{ secrets.CT_SDKS_APP_ID }}
157158 private-key : ${{ secrets.CT_SDKS_APP_PEM }}
158159
159160 - name : Checkout
160- uses : actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4
161+ uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
161162 with :
162163 token : ${{ steps.generate_github_token.outputs.token }}
163164
164- - uses : gradle/wrapper-validation-action@216d1ad2b3710bf005dc39237337b9673fd8fcd5 # v3.3.2
165+ - uses : gradle/wrapper-validation-action@f9c9c575b8b21b6485636a91ffecd10e558c62f6 # v3.5.0
165166
166167 - name : Setup Java
167- uses : actions/setup-java@99b8673ff64fbf99d8d325f52d9a5bdedb8483e9 # v4
168+ uses : actions/setup-java@7a6d8a8234af8eb26422e24e3006232cccaa061b # v4
168169 with :
169170 distribution : ' temurin'
170171 java-version : ' 17'
@@ -181,14 +182,14 @@ jobs:
181182 # Get GitHub token via the CT SDKs App
182183 - name : Generate GitHub token (via CT SDKs App)
183184 id : generate_github_token
184- uses : actions/create-github-app-token@a0de6af83968303c8c955486bf9739a57d23c7f1 # v1
185+ uses : actions/create-github-app-token@c1a285145b9d317df6ced56c09f525b5c2b6f755 # v1
185186 with :
186187 app-id : ${{ secrets.CT_SDKS_APP_ID }}
187188 private-key : ${{ secrets.CT_SDKS_APP_PEM }}
188189 - name : Checkout sources
189- uses : actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4
190+ uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
190191 - name : Generate and submit dependency graph
191192 if : github.event_name == 'workflow_dispatch' || github.event_name == 'push' && github.ref == 'refs/heads/main'
192- uses : gradle/actions/dependency-submission@db19848a5fa7950289d3668fb053140cf3028d43 # v3.3 .2
193+ uses : gradle/actions/dependency-submission@0bdd871935719febd78681f197cd39af5b6e16a6 # v4.2 .2
193194 with :
194195 github-token : ${{ steps.generate_github_token.outputs.token }}
0 commit comments