Skip to content

Commit 1fda4d2

Browse files
committed
pin actions to sha256
Signed-off-by: Appu Goundan <[email protected]>
1 parent 2c30236 commit 1fda4d2

File tree

3 files changed

+4
-4
lines changed

3 files changed

+4
-4
lines changed

.github/workflows/ci.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,7 @@ jobs:
3838
steps:
3939
- uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
4040
- name: Set up JDK ${{ matrix.java-version }}
41-
uses: actions/setup-java@v4
41+
uses: actions/setup-java@6a0805fcefea3d4657a47ac4c165951e33482018 # v4.2.2
4242
with:
4343
java-version: ${{ matrix.java-version }}
4444
distribution: 'temurin'

.github/workflows/conformance.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ jobs:
2727
distribution: 'temurin'
2828

2929
- name: Setup Gradle
30-
uses: gradle/actions/setup-gradle@v4
30+
uses: gradle/actions/setup-gradle@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
3131

3232
- name: Build sigstore-java cli
3333
run: ./gradlew :sigstore-cli:build

.github/workflows/examples.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -21,10 +21,10 @@ jobs:
2121
id-token: write
2222

2323
steps:
24-
- uses: actions/checkout@v4
24+
- uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
2525

2626
- name: Setup Java
27-
uses: actions/setup-java@v4
27+
uses: actions/setup-java@6a0805fcefea3d4657a47ac4c165951e33482018 # v4.2.2
2828
with:
2929
java-version: 11
3030
distribution: 'temurin'

0 commit comments

Comments
 (0)