File tree Expand file tree Collapse file tree 5 files changed +14
-16
lines changed
Expand file tree Collapse file tree 5 files changed +14
-16
lines changed Original file line number Diff line number Diff line change 88 name : Build and Test
99 runs-on : ubuntu-latest
1010 steps :
11- - uses : actions/checkout@v5
11+ - uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
1212 with :
1313 fetch-depth : 0
1414 show-progress : false
15- - uses : actions/setup-java@v5
15+ - uses : actions/setup-java@dded0888837ed1f317902acf8a20df0ad188d165 # v5.0.0
1616 with :
1717 java-version : 25
1818 distribution : ' temurin'
1919 cache : ' maven'
2020 - name : Cache SonarCloud packages
21- uses : actions/cache@v4
21+ uses : actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
2222 with :
2323 path : ~/.sonar/cache
2424 key : ${{ runner.os }}-sonar
@@ -38,13 +38,13 @@ jobs:
3838 env :
3939 GITHUB_TOKEN : ${{ secrets.GITHUB_TOKEN }} # Needed to get PR information, if any
4040 SONAR_TOKEN : ${{ secrets.SONAR_TOKEN }}
41- - uses : actions/upload-artifact@v4
41+ - uses : actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
4242 with :
4343 name : artifacts
4444 path : target/*.jar
4545 - name : Create release
4646 if : startsWith(github.ref, 'refs/tags/')
47- uses : softprops/action-gh-release@v2
47+ uses : softprops/action-gh-release@6da8fa9354ddfdc4aeace5fc48d7f679b5214090 # v2.4.1
4848 with :
4949 token : ${{ secrets.CRYPTOBOT_RELEASE_TOKEN }}
5050 generate_release_notes : true
Original file line number Diff line number Diff line change @@ -16,20 +16,20 @@ jobs:
1616 # dependeabot has on push events only read-only access, but codeql requires write access
1717 if : ${{ !(github.actor == 'dependabot[bot]' && contains(fromJSON('["push"]'), github.event_name)) }}
1818 steps :
19- - uses : actions/checkout@v5
19+ - uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
2020 with :
2121 fetch-depth : 2
2222 show-progress : false
23- - uses : actions/setup-java@v5
23+ - uses : actions/setup-java@dded0888837ed1f317902acf8a20df0ad188d165 # v5.0.0
2424 with :
2525 java-version : 25
2626 distribution : ' temurin'
2727 cache : ' maven'
2828 - name : Initialize CodeQL
29- uses : github/codeql-action/init@v4
29+ uses : github/codeql-action/init@f443b600d91635bebf5b0d9ebc620189c0d6fba5 # v4.30.8
3030 with :
3131 languages : java
3232 - name : Build
3333 run : mvn -B install -DskipTests
3434 - name : Perform CodeQL Analysis
35- uses : github/codeql-action/analyze@v4
35+ uses : github/codeql-action/analyze@f443b600d91635bebf5b0d9ebc620189c0d6fba5 # v4.30.8
Original file line number Diff line number Diff line change 1111
1212jobs :
1313 check-dependencies :
14- uses : skymatic/workflows/.github/workflows/run-dependency-check.yml@v3
14+ uses : skymatic/workflows/.github/workflows/run-dependency-check.yml@1074588008ae3326a2221ea451783280518f0366 # v3.0.1
1515 with :
1616 runner-os : ' ubuntu-latest'
1717 java-distribution : ' temurin'
Original file line number Diff line number Diff line change 77 runs-on : ubuntu-latest
88 if : startsWith(github.ref, 'refs/tags/') # only allow publishing tagged versions
99 steps :
10- - uses : actions/checkout@v5
11- - uses : actions/setup-java@v5
10+ - uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
11+ - uses : actions/setup-java@dded0888837ed1f317902acf8a20df0ad188d165 # v5.0.0
1212 with :
1313 java-version : 25
1414 distribution : ' temurin'
Original file line number Diff line number Diff line change 77 runs-on : ubuntu-latest
88 if : startsWith(github.ref, 'refs/tags/') # only allow publishing tagged versions
99 steps :
10- - uses : actions/checkout@v5
11- with :
12- show-progress : false
13- - uses : actions/setup-java@v5
10+ - uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
11+ - uses : actions/setup-java@dded0888837ed1f317902acf8a20df0ad188d165 # v5.0.0
1412 with :
1513 java-version : 25
1614 distribution : ' temurin'
You can’t perform that action at this time.
0 commit comments