Skip to content

Commit f55a299

Browse files
committed
use signed hashes for github actions
1 parent a6dfc78 commit f55a299

File tree

2 files changed

+12
-12
lines changed

2 files changed

+12
-12
lines changed

.github/workflows/build.yaml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -17,15 +17,15 @@ jobs:
1717
run: sudo apt install -y libpcap-dev
1818

1919
- name: Checkout repository
20-
uses: actions/checkout@v3
20+
uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # v3
2121

2222
- name: Run golangci-lint
23-
uses: reviewdog/action-golangci-lint@v2
23+
uses: reviewdog/action-golangci-lint@f9bba13753278f6a73b27a56a3ffb1bfda90ed71 # v2
2424
with:
2525
go_version: "1.25.4"
2626

2727
- name: Run hadolint
28-
uses: reviewdog/action-hadolint@v1
28+
uses: reviewdog/action-hadolint@921946a7ebaaf08ac72607bad67209f4e52b5407 # v1
2929
build:
3030
runs-on: ubuntu-latest
3131
needs: lint
@@ -34,10 +34,10 @@ jobs:
3434
run: sudo apt install -y libpcap-dev
3535

3636
- name: Checkout source code
37-
uses: actions/checkout@v3
37+
uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # v3
3838

3939
- name: Setup Go
40-
uses: actions/setup-go@v3
40+
uses: actions/setup-go@be3c94b385c4f180051c996d336f57a34c397495 # v3
4141
with:
4242
go-version: '1.24.3'
4343

.github/workflows/docker.yaml

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -20,33 +20,33 @@ jobs:
2020

2121
steps:
2222
- name: Checkout code
23-
uses: actions/checkout@v5
23+
uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5
2424

2525
- name: Set up QEMU
26-
uses: docker/setup-qemu-action@v3
26+
uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130 # v3
2727

2828
- name: Set up Docker Buildx
29-
uses: docker/setup-buildx-action@v3
29+
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3
3030

3131
- name: Install cosign
32-
uses: sigstore/cosign-installer@v3
32+
uses: sigstore/cosign-installer@398d4b0eeef1380460a10c8013a76f728fb906ac # v3
3333

3434
- name: Log in to GHCR
35-
uses: docker/login-action@v3
35+
uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3
3636
with:
3737
registry: ${{ env.GH_REGISTRY }}
3838
username: ${{ github.actor }}
3939
password: ${{ secrets.GITHUB_TOKEN }}
4040

4141
- name: Login to Docker Hub
42-
uses: docker/login-action@v3
42+
uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3
4343
with:
4444
username: ${{ secrets.DOCKERHUB_USERNAME }}
4545
password: ${{ secrets.DOCKERHUB_TOKEN }}
4646

4747
- name: Build and push
4848
id: buildpush
49-
uses: docker/build-push-action@v6
49+
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6
5050
with:
5151
platforms: linux/amd64,linux/arm64
5252
sbom: true

0 commit comments

Comments
 (0)