@@ -12,29 +12,29 @@ jobs:
1212 runs-on : ubuntu-latest
1313 steps :
1414 - name : Checkout code
15- uses : actions/checkout@v6
15+ uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
1616
1717 - name : Set the TAG value
1818 id : get-TAG
1919 run : |
2020 echo "$(make -s log | grep TAG)" >> "$GITHUB_ENV"
2121
2222 - name : Set up QEMU
23- uses : docker/setup-qemu-action@v4
23+ uses : docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a # v4
2424
2525 - name : Set up Docker Buildx
26- uses : docker/setup-buildx-action@v4
26+ uses : docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4
2727
2828 - name : Build container image
29- uses : docker/build-push-action@v7
29+ uses : docker/build-push-action@d08e5c354a6adb9ed34480a06d141179aa583294 # v7
3030 with :
3131 context : .
3232 push : false
3333 tags : rancher/hardened-containerd:${{ env.TAG }}-amd64
3434 file : Dockerfile
3535
3636 - name : Run Trivy vulnerability scanner
37- uses : aquasecurity/trivy-action@0 .35.0
37+ uses : aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # v0 .35.0
3838 with :
3939 image-ref : rancher/hardened-containerd:${{ env.TAG }}-amd64
4040 format : ' table'
@@ -48,21 +48,21 @@ jobs:
4848 runs-on : ubuntu-latest
4949 steps :
5050 - name : Check out code
51- uses : actions/checkout@v6
51+ uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
5252
5353 - name : Set up QEMU
54- uses : docker/setup-qemu-action@v4
54+ uses : docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a # v4
5555
5656 - name : Set up Docker Buildx
57- uses : docker/setup-buildx-action@v4
57+ uses : docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4
5858
5959 - name : Set the TAG value
6060 id : get-TAG
6161 run : |
6262 echo "$(make -s log | grep TAG)" >> "$GITHUB_ENV"
6363
6464 - name : Build container image
65- uses : docker/build-push-action@v7
65+ uses : docker/build-push-action@d08e5c354a6adb9ed34480a06d141179aa583294 # v7
6666 with :
6767 context : .
6868 push : false
7474 ARCH=arm64
7575
7676 - name : Run Trivy vulnerability scanner
77- uses : aquasecurity/trivy-action@0 .35.0
77+ uses : aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # v0 .35.0
7878 with :
7979 image-ref : rancher/hardened-containerd:${{ env.TAG }}-arm64
8080 format : ' table'
@@ -88,20 +88,20 @@ jobs:
8888 runs-on : ubuntu-latest
8989 steps :
9090 - name : Check out code
91- uses : actions/checkout@v6
91+ uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
9292
9393 - name : Set up QEMU
94- uses : docker/setup-qemu-action@v4
94+ uses : docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a # v4
9595
9696 - name : Set up Docker Buildx
97- uses : docker/setup-buildx-action@v4
97+ uses : docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4
9898
9999 - name : Set the TAG value
100100 id : get-TAG
101101 run : |
102102 echo "$(make -s log | grep TAG)" >> "$GITHUB_ENV"
103103 - name : Build container image
104- uses : docker/build-push-action@v7
104+ uses : docker/build-push-action@d08e5c354a6adb9ed34480a06d141179aa583294 # v7
105105 with :
106106 context : .
107107 push : false
@@ -111,7 +111,7 @@ jobs:
111111 platforms : linux/amd64
112112
113113 - name : Run Trivy vulnerability scanner
114- uses : aquasecurity/trivy-action@0 .35.0
114+ uses : aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # v0 .35.0
115115 with :
116116 image-ref : rancher/hardened-containerd:${{ env.TAG }}-amd64-windows
117117 format : ' table'
@@ -120,4 +120,4 @@ jobs:
120120 vuln-type : ' os,library'
121121 severity : ' CRITICAL,HIGH'
122122 continue-on-error : true
123-
123+
0 commit comments