Skip to content

Commit ebb437d

Browse files
committed
fix: Pin actions to SHA and add permissions blocks
1 parent ecdd181 commit ebb437d

18 files changed

+33
-21
lines changed

.github/workflows/agp-matrix.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@ jobs:
2828

2929
steps:
3030
- name: Checkout Repo
31-
uses: actions/checkout@v6
31+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v2
3232
with:
3333
submodules: 'recursive'
3434

.github/workflows/build.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ jobs:
1919

2020
steps:
2121
- name: Checkout Repo
22-
uses: actions/checkout@v6
22+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v2
2323
with:
2424
submodules: 'recursive'
2525

.github/workflows/changelog-preview.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,10 @@ on:
77
- reopened
88
- edited
99
- labeled
10+
permissions:
11+
contents: write
12+
pull-requests: write
13+
1014
jobs:
1115
changelog-preview:
1216
uses: getsentry/craft/.github/workflows/changelog-preview.yml@v2

.github/workflows/changes-in-high-risk-code.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@ jobs:
1616
high_risk_code: ${{ steps.changes.outputs.high_risk_code }}
1717
high_risk_code_files: ${{ steps.changes.outputs.high_risk_code_files }}
1818
steps:
19-
- uses: actions/checkout@v6
19+
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v2
2020
- name: Get changed files
2121
id: changes
2222
uses: dorny/paths-filter@de90cc6fb38fc0963ad72b210f1f284cd68cea36 # v3.0.2

.github/workflows/codeql-analysis.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ jobs:
2020

2121
steps:
2222
- name: Checkout Repo
23-
uses: actions/checkout@v6
23+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v2
2424
with:
2525
submodules: 'recursive'
2626

.github/workflows/enforce-license-compliance.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ jobs:
2020
java-version: '17'
2121

2222
- name: Checkout
23-
uses: actions/checkout@v6
23+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v2
2424

2525
# TODO: remove this when upstream is fixed
2626
- name: Disable Gradle configuration cache (see https://github.com/fossas/fossa-cli/issues/872)

.github/workflows/format-code.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ jobs:
88
runs-on: ubuntu-latest
99
steps:
1010
- name: Checkout
11-
uses: actions/checkout@v6
11+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v2
1212
with:
1313
submodules: 'recursive'
1414

.github/workflows/generate-javadocs.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ jobs:
99
runs-on: ubuntu-latest
1010
steps:
1111
- name: Checkout 🛎️
12-
uses: actions/checkout@v6
12+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v2
1313
with:
1414
submodules: 'recursive'
1515

.github/workflows/integration-tests-benchmarks.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ jobs:
2727

2828
steps:
2929
- name: Git checkout
30-
uses: actions/checkout@v6
30+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v2
3131
with:
3232
submodules: 'recursive'
3333

@@ -77,7 +77,7 @@ jobs:
7777

7878
steps:
7979
- name: Git checkout
80-
uses: actions/checkout@v6
80+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v2
8181
with:
8282
submodules: 'recursive'
8383

.github/workflows/integration-tests-size.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ jobs:
2020

2121
steps:
2222
- name: Checkout Repo
23-
uses: actions/checkout@v6
23+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v2
2424

2525
- name: Setup Java Version
2626
uses: actions/setup-java@v5

0 commit comments

Comments
 (0)