Skip to content

Commit 97164a2

Browse files
authored
Merge pull request #124 from kondukto-io/develop
Pin actions to a full length commit SHA
2 parents 0cbb146 + d76cb14 commit 97164a2

File tree

4 files changed

+18
-18
lines changed

4 files changed

+18
-18
lines changed

.github/workflows/codeql-analysis.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@ jobs:
1616

1717
steps:
1818
- name: Checkout repository
19-
uses: actions/checkout@v4
19+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
2020
with:
2121
# We must fetch at least the immediate parents so that if this is
2222
# a pull request then we can check out the head.
@@ -29,15 +29,15 @@ jobs:
2929

3030
# Initializes the CodeQL tools for scanning.
3131
- name: Initialize CodeQL
32-
uses: github/codeql-action/init@v3
32+
uses: github/codeql-action/init@45775bd8235c68ba998cffa5171334d58593da47
3333
# Override language selection by uncommenting this and choosing your languages
3434
# with:
3535
# languages: go, javascript, csharp, python, cpp, java
3636

3737
# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
3838
# If this step fails, then you should remove it and run the build manually (see below)
3939
- name: Autobuild
40-
uses: github/codeql-action/autobuild@v3
40+
uses: github/codeql-action/autobuild@45775bd8235c68ba998cffa5171334d58593da47
4141

4242
# ℹ️ Command-line programs to run using the OS shell.
4343
# 📚 https://git.io/JvXDl
@@ -51,4 +51,4 @@ jobs:
5151
# make release
5252

5353
- name: Perform CodeQL Analysis
54-
uses: github/codeql-action/analyze@v3
54+
uses: github/codeql-action/analyze@45775bd8235c68ba998cffa5171334d58593da47

.github/workflows/kondukto-gosec.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -34,20 +34,20 @@ jobs:
3434
3535
- name: Checkout Project
3636
id: checkout_project
37-
uses: actions/checkout@v4
37+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
3838
with:
3939
ref: master
4040

4141
- name: Run Gosec Security Scanner
4242
id: run_gosec
43-
uses: securego/gosec@master
43+
uses: securego/gosec@955a68d0d19f4afb7503068f95059f7d0c529017
4444
with:
4545
# we let the report trigger content trigger a failure using the GitHub Security features.
4646
args: "-no-fail -fmt json -out results.json ./..."
4747

4848
- name: Archive GoSec Scan Results
4949
id: archive_gosec_results
50-
uses: actions/upload-artifact@v4
50+
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
5151
with:
5252
name: results.json
5353
path: results.json

.github/workflows/kondukto-nancy.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -34,14 +34,14 @@ jobs:
3434
3535
- name: Checkout Project
3636
id: checkout_project
37-
uses: actions/checkout@v4
37+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
3838
with:
3939
repository: kondukto-io/kdt
4040
ref: master
4141

4242
- name: Setup Go
4343
id: setup_go
44-
uses: actions/setup-go@v5
44+
uses: actions/setup-go@93397bea11091df50f3d7e59dc26a7711a8bcfbe
4545
with:
4646
go-version: 1.23
4747
cache: true
@@ -56,7 +56,7 @@ jobs:
5656
5757
- name: Archive Nancy Scan Results
5858
id: archive_nancy_results
59-
uses: actions/upload-artifact@v4
59+
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
6060
with:
6161
name: results.json
6262
path: results.json

.github/workflows/release.yml

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ jobs:
1414

1515
steps:
1616
- name: Checkout Code
17-
uses: actions/checkout@v4
17+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
1818

1919
- name: Add SHORT_SHA env property
2020
id: set_short_sha_variable
@@ -32,7 +32,7 @@ jobs:
3232
echo "VERSION_TAG=${{ env.GIT_TAG }}" | cut -d '-' -f 1 >> $GITHUB_ENV
3333
3434
- name: Install Go
35-
uses: actions/setup-go@v5
35+
uses: actions/setup-go@93397bea11091df50f3d7e59dc26a7711a8bcfbe
3636
with:
3737
go-version: 1.23.x
3838
cache: true
@@ -64,28 +64,28 @@ jobs:
6464
6565
- name: Upload Release Assets
6666
id: upload-release-assets
67-
uses: dwenegar/upload-release-assets@v1
67+
uses: dwenegar/upload-release-assets@5bc3024cf83521df8ebfadf00ad0c4614fd59148
6868
env:
6969
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
7070
with:
7171
release_id: ${{ steps.create_release.outputs.id }}
7272
assets_path: ./_release/
7373

7474
- name: Set up QEMU
75-
uses: docker/setup-qemu-action@v3
75+
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392
7676

7777
- name: Set up Docker Buildx
78-
uses: docker/setup-buildx-action@v3
78+
uses: docker/setup-buildx-action@b5ca514318bd6ebac0fb2aedd5d36ec1b5c232a2
7979

8080
- name: Login to DockerHub
81-
uses: docker/login-action@v3
81+
uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772
8282
with:
8383
username: ${{ secrets.DOCKERHUB_USERNAME }}
8484
password: ${{ secrets.DOCKERHUB_TOKEN }}
8585

8686
- name: Build/Push Tags
8787
id: docker_build
88-
uses: docker/build-push-action@v6
88+
uses: docker/build-push-action@471d1dc4e07e5cdedd4c2171150001c434f0b7a4
8989
with:
9090
context: .
9191
file: Dockerfile
@@ -101,7 +101,7 @@ jobs:
101101
run: echo ${{ steps.docker_build.outputs.digest }}
102102

103103
- name: Configure AWS credentials
104-
uses: aws-actions/configure-aws-credentials@v4
104+
uses: aws-actions/configure-aws-credentials@ececac1a45f3b08a01d2dd070d28d111c5fe6722
105105
with:
106106
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
107107
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}

0 commit comments

Comments
 (0)