Skip to content

Commit bd3f482

Browse files
authored
[SECENG-364] Pin GitHub Actions to commit SHAs (#37)
1 parent 5a3d2b8 commit bd3f482

File tree

2 files changed

+20
-7
lines changed

2 files changed

+20
-7
lines changed

.github/dependabot.yml

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
version: 2
2+
updates:
3+
- package-ecosystem: "github-actions"
4+
directory: "/"
5+
commit-message:
6+
prefix: "[bot] "
7+
cooldown:
8+
default-days: 7
9+
schedule:
10+
interval: "weekly"
11+
day: "wednesday"
12+
time: "11:00"
13+
timezone: "America/Los_Angeles"

.github/workflows/build-docs.yml

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -8,13 +8,13 @@ jobs:
88
runs-on: ubuntu-latest
99
timeout-minutes: 10
1010
steps:
11-
- uses: actions/checkout@v4
11+
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
1212
with:
1313
lfs: 'true'
1414
- name: Build Jekyll
15-
uses: actions/jekyll-build-pages@v1
15+
uses: actions/jekyll-build-pages@44a6e6beabd48582f863aeeb6cb2151cc1716697 # v1
1616
- name: Upload Jekyll Artifact
17-
uses: actions/upload-artifact@v4.4.0
17+
uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # v4.4.0
1818
with:
1919
name: jekyll-site
2020
path: _site
@@ -25,11 +25,11 @@ jobs:
2525
timeout-minutes: 10
2626
permissions: read-all
2727
steps:
28-
- uses: actions/checkout@v4
28+
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
2929
with:
3030
lfs: 'true'
3131
- name: Download Jekyll Artifact
32-
uses: actions/download-artifact@v4.1.8
32+
uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4.1.8
3333
with:
3434
name: jekyll-site
3535
path: _site
@@ -79,7 +79,7 @@ jobs:
7979
done
8080
8181
- name: Upload Pages artifact
82-
uses: actions/upload-pages-artifact@v3
82+
uses: actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa # v3
8383

8484
# Deploy github pages job
8585
deploy:
@@ -101,4 +101,4 @@ jobs:
101101
steps:
102102
- name: Deploy to GitHub Pages
103103
id: deployment
104-
uses: actions/deploy-pages@v4
104+
uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e # v4

0 commit comments

Comments
 (0)