Skip to content

Commit 1c76bb8

Browse files
chore(deps): pin dependencies
1 parent f3ec89c commit 1c76bb8

15 files changed

+52
-52
lines changed

.github/workflows/backport.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@ jobs:
1616
exit 1
1717
fi
1818
19-
- uses: actions/checkout@v4
19+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
2020
with:
2121
# history is needed to run git cherry-pick below
2222
fetch-depth: 0

.github/workflows/build.yml

Lines changed: 14 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -16,16 +16,16 @@ jobs:
1616
build:
1717
runs-on: ubuntu-latest
1818
steps:
19-
- uses: actions/checkout@v4
19+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
2020

2121
- name: Set up JDK for running Gradle
22-
uses: actions/setup-java@v4
22+
uses: actions/setup-java@3a4f6e1af504cf6a31855fa899c6aa5355ba6c12 # v4
2323
with:
2424
distribution: temurin
2525
java-version: 17
2626

2727
- name: Set up gradle
28-
uses: gradle/actions/setup-gradle@v4
28+
uses: gradle/actions/setup-gradle@94baf225fe0a508e581a564467443d0e2379123b # v4
2929
with:
3030
cache-read-only: ${{ github.event_name == 'pull_request' }}
3131
- name: Gradle build and test
@@ -43,24 +43,24 @@ jobs:
4343
- 20
4444
fail-fast: false
4545
steps:
46-
- uses: actions/checkout@v4
46+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
4747

4848
- id: setup-test-java
4949
name: Set up JDK ${{ matrix.test-java-version }} for running tests
50-
uses: actions/setup-java@v4
50+
uses: actions/setup-java@3a4f6e1af504cf6a31855fa899c6aa5355ba6c12 # v4
5151
with:
5252
# using zulu because new releases get published quickly
5353
distribution: zulu
5454
java-version: ${{ matrix.test-java-version }}
5555

5656
- name: Set up JDK for running Gradle
57-
uses: actions/setup-java@v4
57+
uses: actions/setup-java@3a4f6e1af504cf6a31855fa899c6aa5355ba6c12 # v4
5858
with:
5959
distribution: temurin
6060
java-version: 17
6161

6262
- name: Set up gradle
63-
uses: gradle/actions/setup-gradle@v4
63+
uses: gradle/actions/setup-gradle@94baf225fe0a508e581a564467443d0e2379123b # v4
6464
with:
6565
cache-read-only: ${{ github.event_name == 'pull_request' }}
6666
- name: Gradle test
@@ -73,24 +73,24 @@ jobs:
7373
integration-test:
7474
runs-on: ubuntu-latest
7575
steps:
76-
- uses: actions/checkout@v4
76+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
7777

7878
- name: Set up JDK for running Gradle
79-
uses: actions/setup-java@v4
79+
uses: actions/setup-java@3a4f6e1af504cf6a31855fa899c6aa5355ba6c12 # v4
8080
with:
8181
distribution: temurin
8282
java-version: 17
8383

8484
- name: Set up gradle
85-
uses: gradle/actions/setup-gradle@v4
85+
uses: gradle/actions/setup-gradle@94baf225fe0a508e581a564467443d0e2379123b # v4
8686
with:
8787
cache-read-only: ${{ github.event_name == 'pull_request' }}
8888

8989
- name: Integration test
9090
run: ./gradlew integrationTest
9191

9292
- name: Save integration test results
93-
uses: actions/upload-artifact@v4
93+
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4
9494
if: always()
9595
with:
9696
name: integration-test-results
@@ -125,16 +125,16 @@ jobs:
125125
- integration-test
126126
runs-on: ubuntu-latest
127127
steps:
128-
- uses: actions/checkout@v4
128+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
129129

130130
- name: Set up JDK for running Gradle
131-
uses: actions/setup-java@v4
131+
uses: actions/setup-java@3a4f6e1af504cf6a31855fa899c6aa5355ba6c12 # v4
132132
with:
133133
distribution: temurin
134134
java-version: 17
135135

136136
- name: Set up gradle
137-
uses: gradle/actions/setup-gradle@v4
137+
uses: gradle/actions/setup-gradle@94baf225fe0a508e581a564467443d0e2379123b # v4
138138
# skipping release branches because the versions in those branches are not snapshots
139139
# (also this skips pull requests)
140140
if: ${{ github.ref_name == 'main' && github.repository == 'open-telemetry/opentelemetry-java-contrib' }}

.github/workflows/codeql.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -27,19 +27,19 @@ jobs:
2727
security-events: write # for github/codeql-action/analyze to upload SARIF results
2828
runs-on: ubuntu-latest
2929
steps:
30-
- uses: actions/checkout@v4
30+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
3131

3232
- name: Set up Java 17
33-
uses: actions/setup-java@v4
33+
uses: actions/setup-java@3a4f6e1af504cf6a31855fa899c6aa5355ba6c12 # v4
3434
with:
3535
distribution: temurin
3636
java-version: 17
3737

3838
- name: Set up gradle
39-
uses: gradle/actions/setup-gradle@v4
39+
uses: gradle/actions/setup-gradle@94baf225fe0a508e581a564467443d0e2379123b # v4
4040

4141
- name: Initialize CodeQL
42-
uses: github/codeql-action/init@v3
42+
uses: github/codeql-action/init@dd746615b3b9d728a6a37ca2045b68ca76d4841a # v3
4343
with:
4444
languages: java, actions
4545
# using "latest" helps to keep up with the latest Kotlin support
@@ -53,7 +53,7 @@ jobs:
5353
run: ./gradlew assemble --no-build-cache --no-daemon
5454

5555
- name: Perform CodeQL analysis
56-
uses: github/codeql-action/analyze@v3
56+
uses: github/codeql-action/analyze@dd746615b3b9d728a6a37ca2045b68ca76d4841a # v3
5757

5858
workflow-notification:
5959
needs:

.github/workflows/gradle-wrapper-validation.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,6 @@ jobs:
1111
gradle-wrapper-validation:
1212
runs-on: ubuntu-latest
1313
steps:
14-
- uses: actions/checkout@v4
14+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
1515

16-
- uses: gradle/actions/wrapper-validation@v4.2.2
16+
- uses: gradle/actions/wrapper-validation@94baf225fe0a508e581a564467443d0e2379123b # v4.3.0

.github/workflows/issue-management-feedback-label.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ jobs:
1111
github.event.comment.user.login == github.event.issue.user.login
1212
runs-on: ubuntu-latest
1313
steps:
14-
- uses: actions/checkout@v4
14+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
1515

1616
- name: Remove label
1717
env:

.github/workflows/issue-management-stale-action.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ jobs:
99
stale:
1010
runs-on: ubuntu-latest
1111
steps:
12-
- uses: actions/stale@v9
12+
- uses: actions/stale@5bef64f19d7facfb25b37b414482c7164d639639 # v9
1313
with:
1414
repo-token: ${{ secrets.GITHUB_TOKEN }}
1515
days-before-stale: 7

.github/workflows/ossf-scorecard.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ jobs:
1919
# Needed for GitHub OIDC token if publish_results is true
2020
id-token: write
2121
steps:
22-
- uses: actions/checkout@v4
22+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
2323
with:
2424
persist-credentials: false
2525

@@ -33,7 +33,7 @@ jobs:
3333
# uploads of run results in SARIF format to the repository Actions tab.
3434
# https://docs.github.com/en/actions/advanced-guides/storing-workflow-data-as-artifacts
3535
- name: "Upload artifact"
36-
uses: actions/upload-artifact@v4
36+
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4
3737
with:
3838
name: SARIF file
3939
path: results.sarif
@@ -42,6 +42,6 @@ jobs:
4242
# Upload the results to GitHub's code scanning dashboard (optional).
4343
# Commenting out will disable upload of results to your repo's Code Scanning dashboard
4444
- name: "Upload to code-scanning"
45-
uses: github/codeql-action/upload-sarif@v3
45+
uses: github/codeql-action/upload-sarif@dd746615b3b9d728a6a37ca2045b68ca76d4841a # v3
4646
with:
4747
sarif_file: results.sarif

.github/workflows/prepare-patch-release.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ jobs:
66
prepare-patch-release:
77
runs-on: ubuntu-latest
88
steps:
9-
- uses: actions/checkout@v4
9+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
1010

1111
- run: |
1212
if [[ ! $GITHUB_REF_NAME =~ ^release/v[0-9]+\.[0-9]+\.x$ ]]; then

.github/workflows/prepare-release-branch.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ jobs:
66
prereqs:
77
runs-on: ubuntu-latest
88
steps:
9-
- uses: actions/checkout@v4
9+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
1010

1111
- name: Verify prerequisites
1212
run: |
@@ -25,7 +25,7 @@ jobs:
2525
needs:
2626
- prereqs
2727
steps:
28-
- uses: actions/checkout@v4
28+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
2929

3030
- name: Create release branch
3131
run: |
@@ -74,7 +74,7 @@ jobs:
7474
needs:
7575
- prereqs
7676
steps:
77-
- uses: actions/checkout@v4
77+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
7878

7979
- name: Set environment variables
8080
run: |

.github/workflows/release.yml

Lines changed: 15 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -6,20 +6,20 @@ jobs:
66
build:
77
runs-on: ubuntu-latest
88
steps:
9-
- uses: actions/checkout@v4
9+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
1010

1111
- name: Set up JDK for running Gradle
12-
uses: actions/setup-java@v4
12+
uses: actions/setup-java@3a4f6e1af504cf6a31855fa899c6aa5355ba6c12 # v4
1313
with:
1414
distribution: temurin
1515
java-version: 17
1616

1717
- name: Set up gradle
18-
uses: gradle/actions/setup-gradle@v4
18+
uses: gradle/actions/setup-gradle@94baf225fe0a508e581a564467443d0e2379123b # v4
1919
- name: Gradle build
2020
run: ./gradlew build
2121

22-
- uses: actions/upload-artifact@v4
22+
- uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4
2323
name: Save unit test results
2424
if: always()
2525
with:
@@ -29,20 +29,20 @@ jobs:
2929
integration-test:
3030
runs-on: ubuntu-latest
3131
steps:
32-
- uses: actions/checkout@v4
32+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
3333

3434
- name: Set up JDK for running Gradle
35-
uses: actions/setup-java@v4
35+
uses: actions/setup-java@3a4f6e1af504cf6a31855fa899c6aa5355ba6c12 # v4
3636
with:
3737
distribution: temurin
3838
java-version: 17
3939

4040
- name: Set up gradle
41-
uses: gradle/actions/setup-gradle@v4
41+
uses: gradle/actions/setup-gradle@94baf225fe0a508e581a564467443d0e2379123b # v4
4242
- name: Integration test
4343
run: ./gradlew integrationTest
4444

45-
- uses: actions/upload-artifact@v4
45+
- uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4
4646
name: Save integration test results
4747
if: always()
4848
with:
@@ -63,7 +63,7 @@ jobs:
6363
exit 1
6464
fi
6565
66-
- uses: actions/checkout@v4
66+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
6767

6868
- name: Set environment variables
6969
run: |
@@ -92,7 +92,7 @@ jobs:
9292
9393
# check out main branch to verify there won't be problems with merging the change log
9494
# at the end of this workflow
95-
- uses: actions/checkout@v4
95+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
9696
with:
9797
ref: main
9898

@@ -107,19 +107,19 @@ jobs:
107107
fi
108108
109109
# back to the release branch
110-
- uses: actions/checkout@v4
110+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
111111
with:
112112
# tags are needed for the generate-release-contributors.sh script
113113
fetch-depth: 0
114114

115115
- name: Set up JDK for running Gradle
116-
uses: actions/setup-java@v4
116+
uses: actions/setup-java@3a4f6e1af504cf6a31855fa899c6aa5355ba6c12 # v4
117117
with:
118118
distribution: temurin
119119
java-version: 17
120120

121121
- name: Set up gradle
122-
uses: gradle/actions/setup-gradle@v4
122+
uses: gradle/actions/setup-gradle@94baf225fe0a508e581a564467443d0e2379123b # v4
123123
- name: Build and publish artifacts
124124
run: ./gradlew assemble publishToSonatype closeAndReleaseSonatypeStagingRepository
125125
env:
@@ -190,7 +190,7 @@ jobs:
190190
needs:
191191
- release
192192
steps:
193-
- uses: actions/checkout@v4
193+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
194194

195195
- name: Copy change log section from release branch
196196
env:
@@ -199,7 +199,7 @@ jobs:
199199
sed -n "0,/^## Version $VERSION /d;/^## Version /q;p" CHANGELOG.md \
200200
> /tmp/changelog-section.md
201201
202-
- uses: actions/checkout@v4
202+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
203203
with:
204204
ref: main
205205

0 commit comments

Comments
 (0)