2323 id-token : write
2424 steps :
2525 - name : Checkout repository
26- uses : actions/checkout@v4
26+ uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
2727
2828 - name : Log in to the Container registry
2929 uses : docker/login-action@65b78e6e13532edd9afa3aa52ac7964289d1a9c1
@@ -39,10 +39,10 @@ jobs:
3939 images : ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
4040
4141 - name : Set up QEMU
42- uses : docker/setup-qemu-action@v3
42+ uses : docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3
4343
4444 - name : Set up Docker Buildx
45- uses : docker/setup-buildx-action@v3
45+ uses : docker/setup-buildx-action@b5ca514318bd6ebac0fb2aedd5d36ec1b5c232a2 # v3
4646
4747 - name : Build and push Docker image
4848 id : push
@@ -56,15 +56,15 @@ jobs:
5656
5757 - name : Generate artifact attestation
5858 if : ${{ github.event_name == 'push' || github.event_name == 'workflow_dispatch' }}
59- uses : actions/attest-build-provenance@v2
59+ uses : actions/attest-build-provenance@c074443f1aee8d4aeeae555aebba3282517141b2 # v2
6060 with :
6161 subject-name : ${{ env.REGISTRY }}/${{ env.IMAGE_NAME}}
6262 subject-digest : ${{ steps.push.outputs.digest }}
6363 push-to-registry : true
6464
6565 - name : Update release
6666 if : ${{ github.event_name == 'push' || github.event_name == 'workflow_dispatch' }}
67- uses : ncipollo/release-action@v1
67+ uses : ncipollo/release-action@440c8c1cb0ed28b9f43e4d1d670870f059653174 # v1
6868 with :
6969 allowUpdates : true
7070 updateOnlyUnreleased : true
0 commit comments