Skip to content

Commit d8dd6e0

Browse files
authored
Merge pull request #2396 from ricardoapl/pin-github-actions
chore: pin dependencies in GitHub Actions by hash
2 parents 7caed23 + b983ed5 commit d8dd6e0

File tree

4 files changed

+21
-21
lines changed

4 files changed

+21
-21
lines changed

.github/workflows/ci.yml

Lines changed: 17 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -29,10 +29,10 @@ jobs:
2929
runs-on: ubuntu-latest
3030
steps:
3131
- name: Check out code into the Go module directory
32-
uses: actions/checkout@v4
32+
uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
3333

3434
- name: Set up Go 1.x
35-
uses: actions/setup-go@v5
35+
uses: actions/setup-go@cdcb36043654635271a94b9a6d1392de5bb323a7 # v5.0.1
3636
with:
3737
go-version: ${{ env.GO_VERSION }}
3838
id: go
@@ -51,10 +51,10 @@ jobs:
5151
runs-on: ubuntu-latest
5252
steps:
5353
- name: Check out code into the Go module directory
54-
uses: actions/checkout@v4
54+
uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
5555

5656
- name: Set up Go 1.x
57-
uses: actions/setup-go@v5
57+
uses: actions/setup-go@cdcb36043654635271a94b9a6d1392de5bb323a7 # v5.0.1
5858
with:
5959
go-version: ${{ env.GO_VERSION }}
6060
id: go
@@ -72,10 +72,10 @@ jobs:
7272
runs-on: ubuntu-latest
7373
steps:
7474
- name: Check out code into the Go module directory
75-
uses: actions/checkout@v4
75+
uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
7676

7777
- name: Set up Go 1.x
78-
uses: actions/setup-go@v5
78+
uses: actions/setup-go@cdcb36043654635271a94b9a6d1392de5bb323a7 # v5.0.1
7979
with:
8080
go-version: ${{ env.GO_VERSION }}
8181
id: go
@@ -93,10 +93,10 @@ jobs:
9393
runs-on: ubuntu-latest
9494
steps:
9595
- name: Check out code into the Go module directory
96-
uses: actions/checkout@v4
96+
uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
9797

9898
- name: Set up Go 1.x
99-
uses: actions/setup-go@v5
99+
uses: actions/setup-go@cdcb36043654635271a94b9a6d1392de5bb323a7 # v5.0.1
100100
with:
101101
go-version: ${{ env.GO_VERSION }}
102102
id: go
@@ -114,10 +114,10 @@ jobs:
114114
runs-on: ubuntu-latest
115115
steps:
116116
- name: Check out code into the Go module directory
117-
uses: actions/checkout@v4
117+
uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
118118

119119
- name: Set up Go 1.x
120-
uses: actions/setup-go@v5
120+
uses: actions/setup-go@cdcb36043654635271a94b9a6d1392de5bb323a7 # v5.0.1
121121
with:
122122
go-version: ${{ env.GO_VERSION }}
123123
id: go
@@ -135,7 +135,7 @@ jobs:
135135
runs-on: ubuntu-latest
136136
steps:
137137
- name: Check out code into the Go module directory
138-
uses: actions/checkout@v4
138+
uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
139139

140140
- name: Setup promtool
141141
run: |
@@ -150,10 +150,10 @@ jobs:
150150
runs-on: ubuntu-latest
151151
steps:
152152
- name: Check out code into the Go module directory
153-
uses: actions/checkout@v4
153+
uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
154154

155155
- name: Set up Go 1.x
156-
uses: actions/setup-go@v5
156+
uses: actions/setup-go@cdcb36043654635271a94b9a6d1392de5bb323a7 # v5.0.1
157157
with:
158158
go-version: ${{ env.GO_VERSION }}
159159
id: go
@@ -171,10 +171,10 @@ jobs:
171171
runs-on: ubuntu-latest
172172
steps:
173173
- name: Check out code into the Go module directory
174-
uses: actions/checkout@v4
174+
uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
175175

176176
- name: Set up Go 1.x
177-
uses: actions/setup-go@v5
177+
uses: actions/setup-go@cdcb36043654635271a94b9a6d1392de5bb323a7 # v5.0.1
178178
with:
179179
go-version: ${{ env.GO_VERSION }}
180180
id: go
@@ -192,10 +192,10 @@ jobs:
192192
runs-on: ubuntu-latest
193193
steps:
194194
- name: Check out code into the Go module directory
195-
uses: actions/checkout@v4
195+
uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
196196

197197
- name: Set up Go 1.x
198-
uses: actions/setup-go@v5
198+
uses: actions/setup-go@cdcb36043654635271a94b9a6d1392de5bb323a7 # v5.0.1
199199
with:
200200
go-version: ${{ env.GO_VERSION }}
201201
id: go

.github/workflows/govulncheck.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,10 +15,10 @@ jobs:
1515
ci-security-checks:
1616
runs-on: ubuntu-latest
1717
steps:
18-
- uses: actions/checkout@v4
18+
- uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
1919
name: Checkout code
2020
- name: Set up Go 1.x
21-
uses: actions/setup-go@v5
21+
uses: actions/setup-go@cdcb36043654635271a94b9a6d1392de5bb323a7 # v5.0.1
2222
with:
2323
go-version: ${{ env.GO_VERSION }}
2424
- name: Install govulncheck binary

.github/workflows/openvex.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ jobs:
99
runs-on: ubuntu-latest
1010
steps:
1111
- name: Checkout code
12-
uses: actions/checkout@v4
12+
uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
1313
- name: Set environment variables
1414
run: echo "RELEASE_VERSION=${GITHUB_REF#refs/*/}" >> $GITHUB_ENV
1515
- uses: openvex/generate-vex@c59881b41451d7ccba5c3b74cd195382b8971fcd

.github/workflows/semantic.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,6 @@ jobs:
1818
name: Validate PR title for semantic commit message
1919
runs-on: ubuntu-latest
2020
steps:
21-
- uses: amannn/action-semantic-pull-request@v5
21+
- uses: amannn/action-semantic-pull-request@e9fabac35e210fea40ca5b14c0da95a099eff26f # v5.4.0
2222
env:
2323
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

0 commit comments

Comments
 (0)