Skip to content

Commit 7730f7e

Browse files
authored
tighten security for dependency updates (#1685)
1 parent 2022f7b commit 7730f7e

File tree

6 files changed

+23
-10
lines changed

6 files changed

+23
-10
lines changed

.github/dependabot.yml

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,19 +2,28 @@ version: 2
22
updates:
33
- package-ecosystem: "npm"
44
directory: "/"
5+
cooldown:
6+
default-days: 7
57
schedule:
68
interval: weekly
79
time: "01:00"
810
timezone: "Europe/Brussels"
911
groups:
1012
production-dependencies:
1113
dependency-type: "production"
14+
exclude-patterns:
15+
- "@webref/css"
1216
patterns:
1317
- "*"
1418
development-dependencies:
1519
dependency-type: "development"
20+
exclude-patterns:
21+
- "@webref/css"
1622
patterns:
1723
- "*"
24+
webref-css:
25+
patterns:
26+
- "@webref/css"
1827
open-pull-requests-limit: 5
1928
versioning-strategy: increase
2029
rebase-strategy: auto
@@ -23,6 +32,8 @@ updates:
2332
- "/e2e"
2433
- "/e2e-package-managers/yarn"
2534
- "/sites"
35+
cooldown:
36+
default-days: 7
2637
schedule:
2738
interval: weekly
2839
time: "01:00"
@@ -36,6 +47,8 @@ updates:
3647
rebase-strategy: auto
3748
- package-ecosystem: "github-actions"
3849
directory: "/"
50+
cooldown:
51+
default-days: 7
3952
schedule:
4053
interval: weekly
4154
time: "01:00"

.github/workflows/codeql.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -21,10 +21,10 @@ jobs:
2121

2222
steps:
2323
- name: Checkout repository
24-
uses: actions/checkout@v5
24+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
2525

2626
- name: Initialize CodeQL
27-
uses: github/codeql-action/init@v3
27+
uses: github/codeql-action/init@192325c86100d080feab897ff886c34abd4c83a3
2828
with:
2929
languages: ${{ matrix.language }}
3030
queries: security-extended
@@ -39,4 +39,4 @@ jobs:
3939
- run: npm run build --workspaces --if-present
4040

4141
- name: Perform CodeQL Analysis
42-
uses: github/codeql-action/analyze@v3
42+
uses: github/codeql-action/analyze@192325c86100d080feab897ff886c34abd4c83a3

.github/workflows/deploy-preset-env.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,10 +17,10 @@ jobs:
1717
name: Request Netlify Webhook
1818
runs-on: ubuntu-latest
1919
steps:
20-
- uses: actions/checkout@v5
20+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
2121
with:
2222
fetch-depth: 1
23-
- uses: actions/setup-node@v5
23+
- uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444
2424
with:
2525
node-version: 24
2626

.github/workflows/labeler.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ jobs:
1010
triage:
1111
runs-on: ubuntu-latest
1212
steps:
13-
- uses: actions/labeler@v6
13+
- uses: actions/labeler@634933edcd8ababfe52f92936142cc22ac488b1b
1414
with:
1515
repo-token: "${{ secrets.GITHUB_TOKEN }}"
1616

.github/workflows/lint.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,10 +14,10 @@ jobs:
1414
lint:
1515
runs-on: ubuntu-latest
1616
steps:
17-
- uses: actions/checkout@v5
17+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
1818
with:
1919
fetch-depth: 1
20-
- uses: actions/setup-node@v5
20+
- uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444
2121
with:
2222
node-version: 24
2323

.github/workflows/test.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -31,10 +31,10 @@ jobs:
3131
- node: 24
3232
is_base_node_version: true
3333
steps:
34-
- uses: actions/checkout@v5
34+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
3535
with:
3636
fetch-depth: 1
37-
- uses: actions/setup-node@v5
37+
- uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444
3838
with:
3939
node-version: ${{ matrix.node }}
4040

0 commit comments

Comments
 (0)