Skip to content

Commit d79f30d

Browse files
authored
CI: pin actions (#200)
1 parent d0c79a8 commit d79f30d

File tree

3 files changed

+12
-12
lines changed

3 files changed

+12
-12
lines changed

.github/workflows/cifuzz.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -25,14 +25,14 @@ jobs:
2525
fuzz-seconds: 800
2626
output-sarif: true
2727
- name: Upload Crash
28-
uses: actions/upload-artifact@v4
28+
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
2929
if: failure() && steps.build.outcome == 'success'
3030
with:
3131
name: artifacts
3232
path: ./out/artifacts
3333
- name: Upload Sarif
3434
if: always() && steps.build.outcome == 'success'
35-
uses: github/codeql-action/upload-sarif@v3
35+
uses: github/codeql-action/upload-sarif@192325c86100d080feab897ff886c34abd4c83a3 # v3.30.3
3636
with:
3737
# Path to SARIF file relative to the root of the repository
3838
sarif_file: cifuzz-sarif/results.sarif

.github/workflows/codeql.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -24,21 +24,21 @@ jobs:
2424

2525
steps:
2626
- name: Clone repository
27-
uses: actions/checkout@v4
27+
uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
2828
with:
2929
persist-credentials: false
3030

3131
- name: Initialize CodeQL
32-
uses: github/codeql-action/init@v3
32+
uses: github/codeql-action/init@192325c86100d080feab897ff886c34abd4c83a3 # v3.30.3
3333
with:
3434
languages: cpp
3535
queries: security-extended
3636
config-file: ./.github/codeql/codeql-config.yml
3737

3838
# Install CMake
39-
- uses: lukka/get-cmake@v4.0.1
39+
- uses: lukka/get-cmake@57c20a23a6cac5b90f31864439996e5b206df9dc # v4.0.1
4040
# Install NASM
41-
- uses: ilammy/setup-nasm@v1
41+
- uses: ilammy/setup-nasm@72793074d3c8cdda771dba85f6deafe00623038b # v1.5.2
4242

4343
# Initialize the CMake directory and build
4444
- name: Build
@@ -47,6 +47,6 @@ jobs:
4747
cmake --build build --config Release
4848
4949
- name: Perform CodeQL Analysis
50-
uses: github/codeql-action/analyze@v3
50+
uses: github/codeql-action/analyze@192325c86100d080feab897ff886c34abd4c83a3 # v3.30.3
5151
with:
5252
category: "/language:cpp"

.github/workflows/compile.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -24,16 +24,16 @@ jobs:
2424
triplet: x64-osx
2525
steps:
2626
- name: Clone repository
27-
uses: actions/checkout@v4
27+
uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
2828
with:
2929
persist-credentials: false
3030

3131
# Install CMake
32-
- uses: lukka/get-cmake@v4.0.1
32+
- uses: lukka/get-cmake@57c20a23a6cac5b90f31864439996e5b206df9dc # v4.0.1
3333
# Install NASM
34-
- uses: ilammy/setup-nasm@v1
34+
- uses: ilammy/setup-nasm@72793074d3c8cdda771dba85f6deafe00623038b # v1.5.2
3535
# Launch the MSVC Tools Command Prompt (Windows)
36-
- uses: ilammy/msvc-dev-cmd@v1
36+
- uses: ilammy/msvc-dev-cmd@0b201ec74fa43914dc39ae48a89fd1d8cb592756 # v1.13.0
3737

3838
# Initialize the CMake directory and build
3939
- name: Build
@@ -56,7 +56,7 @@ jobs:
5656
shell: bash
5757

5858
# Upload the compiled binary
59-
- uses: actions/upload-artifact@v4
59+
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
6060
if: matrix.os != 'ubuntu-latest'
6161
with:
6262
name: jpegoptim-${{ matrix.triplet }}

0 commit comments

Comments
 (0)