File tree Expand file tree Collapse file tree 7 files changed +23
-23
lines changed
Expand file tree Collapse file tree 7 files changed +23
-23
lines changed Original file line number Diff line number Diff line change @@ -36,31 +36,31 @@ jobs:
3636 timeout-minutes : 60
3737 steps :
3838 - name : Checkout
39- uses : actions/checkout@v6
39+ uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
4040
4141 - name : Read Docker Hub credentials
4242 if : ${{ inputs.push }}
43- uses : rancher-eio/read-vault-secrets@main
43+ uses : rancher-eio/read-vault-secrets@0da85151ad1f19ed7986c41587e45aac1ace74b6 # v3
4444 with :
4545 secrets : |
4646 secret/data/github/repo/${{ github.repository }}/dockerhub/rancher/credentials username | DOCKER_USERNAME ;
4747 secret/data/github/repo/${{ github.repository }}/dockerhub/rancher/credentials password | DOCKER_PASSWORD
4848
4949 - name : Set up QEMU
50- uses : docker/setup-qemu-action@v3
50+ uses : docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130 # v3
5151
5252 - name : Set up Docker Buildx
53- uses : docker/setup-buildx-action@v3
53+ uses : docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3
5454
5555 - name : Log in to Docker Hub
5656 if : ${{ inputs.push }}
57- uses : docker/login-action@v3
57+ uses : docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3
5858 with :
5959 username : ${{ env.DOCKER_USERNAME }}
6060 password : ${{ env.DOCKER_PASSWORD }}
6161
6262 - name : Build and push
63- uses : docker/build-push-action@v7
63+ uses : docker/build-push-action@d08e5c354a6adb9ed34480a06d141179aa583294 # v7
6464 with :
6565 context : .
6666 file : ./Dockerfile
Original file line number Diff line number Diff line change 5959 # your codebase is analyzed, see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages
6060 steps :
6161 - name : Checkout repository
62- uses : actions/checkout@v6
62+ uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
6363
6464 # Add any setup steps before running the `github/codeql-action/init` action.
6565 # This includes steps like installing compilers or runtimes (`actions/setup-node`
6969
7070 # Initializes the CodeQL tools for scanning.
7171 - name : Initialize CodeQL
72- uses : github/codeql-action/init@v4
72+ uses : github/codeql-action/init@38697555549f1db7851b81482ff19f1fa5c4fedc # v4
7373 with :
7474 languages : ${{ matrix.language }}
7575 build-mode : ${{ matrix.build-mode }}
9898 exit 1
9999
100100 - name : Perform CodeQL Analysis
101- uses : github/codeql-action/analyze@v4
101+ uses : github/codeql-action/analyze@38697555549f1db7851b81482ff19f1fa5c4fedc # v4
102102 with :
103103 category : " /language:${{matrix.language}}"
Original file line number Diff line number Diff line change @@ -20,13 +20,13 @@ jobs:
2020 # The FOSSA token is shared between all repos in Harvester's GH org. It can
2121 # be used directly and there is no need to request specific access to EIO.
2222 - name : Read FOSSA token
23- uses : rancher-eio/read-vault-secrets@main
23+ uses : rancher-eio/read-vault-secrets@0da85151ad1f19ed7986c41587e45aac1ace74b6 # v3
2424 with :
2525 secrets : |
2626 secret/data/github/org/harvester/fossa/credentials token | FOSSA_API_KEY_PUSH_ONLY
2727
2828 - name : FOSSA scan
29- uses : fossas/fossa-action@main
29+ uses : fossas/fossa-action@c414b9ad82eaad041e47a7cf62a4f02411f427a0 # v1.8.0
3030 with :
3131 api-key : ${{ env.FOSSA_API_KEY_PUSH_ONLY }}
3232 # Only runs the scan and do not provide/returns any results back to the
Original file line number Diff line number Diff line change @@ -16,15 +16,15 @@ jobs:
1616 runs-on : ubuntu-latest
1717 steps :
1818 - name : Checkout
19- uses : actions/checkout@v6
19+ uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
2020
2121 - name : Setup Go
22- uses : actions/setup-go@v6
22+ uses : actions/setup-go@4b73464bb391d4059bd26b0524d20df3927bd417 # v6
2323 with :
2424 go-version-file : go.mod
2525
2626 - name : Run linter
27- uses : golangci/golangci-lint-action@v9
27+ uses : golangci/golangci-lint-action@1e7e51e771db61008b38414a730f564565cf7c20 # v9
2828 with :
2929 version : v2.8.0
3030
@@ -33,10 +33,10 @@ jobs:
3333 runs-on : ubuntu-latest
3434 steps :
3535 - name : Checkout
36- uses : actions/checkout@v6
36+ uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
3737
3838 - name : Setup Go
39- uses : actions/setup-go@v6
39+ uses : actions/setup-go@4b73464bb391d4059bd26b0524d20df3927bd417 # v6
4040 with :
4141 go-version-file : go.mod
4242
@@ -50,10 +50,10 @@ jobs:
5050 runs-on : ubuntu-latest
5151 steps :
5252 - name : Checkout
53- uses : actions/checkout@v6
53+ uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
5454
5555 - name : Setup Go
56- uses : actions/setup-go@v6
56+ uses : actions/setup-go@4b73464bb391d4059bd26b0524d20df3927bd417 # v6
5757 with :
5858 go-version-file : go.mod
5959
Original file line number Diff line number Diff line change 1616 steps :
1717 - name : Extract Docker metadata
1818 id : meta
19- uses : docker/metadata-action@v6
19+ uses : docker/metadata-action@030e881283bb7a6894de51c315a6bfe6a94e05cf # v6
2020 with :
2121 images : rancher/harvester-upgrade-toolkit
2222 tags : |
Original file line number Diff line number Diff line change @@ -17,10 +17,10 @@ jobs:
1717 runs-on : ubuntu-latest
1818 steps :
1919 - name : Clone the code
20- uses : actions/checkout@v6
20+ uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
2121
2222 - name : Setup Go
23- uses : actions/setup-go@v6
23+ uses : actions/setup-go@4b73464bb391d4059bd26b0524d20df3927bd417 # v6
2424 with :
2525 go-version-file : go.mod
2626
Original file line number Diff line number Diff line change @@ -17,10 +17,10 @@ jobs:
1717 runs-on : ubuntu-latest
1818 steps :
1919 - name : Clone the code
20- uses : actions/checkout@v6
20+ uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
2121
2222 - name : Setup Go
23- uses : actions/setup-go@v6
23+ uses : actions/setup-go@4b73464bb391d4059bd26b0524d20df3927bd417 # v6
2424 with :
2525 go-version-file : go.mod
2626
You can’t perform that action at this time.
0 commit comments