File tree Expand file tree Collapse file tree 8 files changed +13
-13
lines changed
Expand file tree Collapse file tree 8 files changed +13
-13
lines changed Original file line number Diff line number Diff line change @@ -9,11 +9,11 @@ inputs:
99runs :
1010 using : composite
1111 steps :
12- - uses : actions/cache@1bd1e32a3bdc45362d1e726936510720a7c30a57 # v4.2.0
12+ - uses : actions/cache@d4323d4df104b026a6aa633fdb11d772146be0bf # v4.2.2
1313 with :
1414 path : ~/go/pkg/mod
1515 key : ${{ runner.os }}-go-pkg-mod-${{ hashFiles('**/go.sum') }}-${{ hashFiles('Makefile') }}
16- - uses : actions/cache@1bd1e32a3bdc45362d1e726936510720a7c30a57 # v4.2.0
16+ - uses : actions/cache@d4323d4df104b026a6aa633fdb11d772146be0bf # v4.2.2
1717 if : ${{ inputs.build-cache-key }}
1818 with :
1919 path : ~/.cache/go-build
Original file line number Diff line number Diff line change 1717 - name : Checkout
1818 uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
1919 - name : Ensure SHA pinned actions
20- uses : zgosalvez/github-actions-ensure-sha-pinned-actions@6eb1abde32fed00453b0d03497f4ba4fecba146d # v3.0.21
20+ uses : zgosalvez/github-actions-ensure-sha-pinned-actions@25ed13d0628a1601b4b44048e63cc4328ed03633 # v3.0.22
2121 with :
2222 # slsa-github-generator requires using a semver tag for reusable workflows.
2323 # See: https://github.com/slsa-framework/slsa-github-generator#referencing-slsa-builders-and-generators
Original file line number Diff line number Diff line change 5252 with :
5353 go-version-file : ' go.mod'
5454 - name : Run Gosec Security Scanner
55- uses : securego/gosec@e0cca6fe95306b7e7790d6f1bf6a7bec6d622459 # v2.22.0
55+ uses : securego/gosec@43fee884f668c23601e0bec7a8c095fba226f889 # v2.22.1
5656 with :
5757 args : ' -no-fail -fmt sarif -out gosec.sarif ./...'
5858 - name : Upload SARIF file
7777 value : ${{ secrets.CODECOV_TOKEN }}
7878 - name : Upload Report to Codecov
7979 if : ${{ steps.checksecret.outputs.result == 'true' }}
80- uses : codecov/codecov-action@13ce06bfc6bbe3ecf90edbbf1bc32fe5978ca1d3 # v5.3.1
80+ uses : codecov/codecov-action@0565863a31f2c772f9f0395002a31e3f06189574 # v5.4.0
8181 with :
8282 token : ${{ secrets.CODECOV_TOKEN }}
8383 slug : projectcapsule/capsule-proxy
Original file line number Diff line number Diff line change 3636 output : ' trivy-results.sarif'
3737 severity : ' CRITICAL,HIGH'
3838 - name : Install Cosign
39- uses : sigstore/cosign-installer@c56c2d3e59e4281cc41dea2217323ba5694b171e # v3.8.0
39+ uses : sigstore/cosign-installer@d7d6bc7722e3daa8354c50bcb52f4837da5e9b6a # v3.8.1
4040 - name : Publish Capsule
4141 id : publish-capsule
4242 uses : peak-scale/github-actions/make-ko-publish@a441cca016861c546ab7e065277e40ce41a3eb84 # v0.2.0
Original file line number Diff line number Diff line change 4545 chart-digest : ${{ steps.helm_publish.outputs.digest }}
4646 steps :
4747 - uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
48- - uses : sigstore/cosign-installer@c56c2d3e59e4281cc41dea2217323ba5694b171e # v3.8.0
48+ - uses : sigstore/cosign-installer@d7d6bc7722e3daa8354c50bcb52f4837da5e9b6a # v3.8.1
4949 - name : " Extract Version"
5050 id : extract_version
5151 run : |
Original file line number Diff line number Diff line change 2828 - uses : creekorful/goreportcard-action@1f35ced8cdac2cba28c9a2f2288a16aacfd507f9 # v1.0
2929 - uses : anchore/sbom-action/download-syft@79202aee38a39bd2039be442e58d731b63baf740
3030 - name : Install Cosign
31- uses : sigstore/cosign-installer@c56c2d3e59e4281cc41dea2217323ba5694b171e # v3.8.0
31+ uses : sigstore/cosign-installer@d7d6bc7722e3daa8354c50bcb52f4837da5e9b6a # v3.8.1
3232 - name : Run GoReleaser
33- uses : goreleaser/goreleaser-action@9ed2f89a662bf1735a48bc8557fd212fa902bebf # v6.1.0
33+ uses : goreleaser/goreleaser-action@90a3faa9d0182683851fbfa97ca1a2cb983bfca3 # v6.2.1
3434 with :
3535 version : latest
3636 args : release --clean --timeout 90m
Original file line number Diff line number Diff line change @@ -24,19 +24,19 @@ jobs:
2424 with :
2525 persist-credentials : false
2626 - name : Run analysis
27- uses : ossf/scorecard-action@62b2cac7ed8198b15735ed49ab1e5cf35480ba46 # v2.4.0
27+ uses : ossf/scorecard-action@f49aabe0b5af0936a0987cfb85d86b75731b0186 # v2.4.1
2828 with :
2929 results_file : results.sarif
3030 results_format : sarif
3131 repo_token : ${{ secrets.SCORECARD_READ_TOKEN }}
3232 publish_results : true
3333 - name : Upload artifact
34- uses : actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
34+ uses : actions/upload-artifact@4cec3d8aa04e39d1a68397de0c4cd6fb9dce8ec1 # v4.6.1
3535 with :
3636 name : SARIF file
3737 path : results.sarif
3838 retention-days : 5
3939 - name : Upload to code-scanning
40- uses : github/codeql-action/upload-sarif@9e8d0789d4a0fa9ceb6b1738f7e269594bdd67f0 # v3.28.9
40+ uses : github/codeql-action/upload-sarif@b56ba49b26e50535fa1e7f7db0f4f7b4bf65d80d # v3.28.10
4141 with :
4242 sarif_file : results.sarif
Original file line number Diff line number Diff line change 1919 chart :
2020 spec :
2121 chart : capsule
22- version : " 0.7.3 "
22+ version : " 0.7.4 "
2323 sourceRef :
2424 kind : HelmRepository
2525 name : projectcapsule
You can’t perform that action at this time.
0 commit comments