Skip to content

Commit 514d06b

Browse files
committed
fix: pin actions to commit SHA
Signed-off-by: Shane Utt <shaneutt@linux.com>
1 parent f1525a6 commit 514d06b

5 files changed

Lines changed: 9 additions & 9 deletions

File tree

.github/workflows/audit.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,14 +20,14 @@ jobs:
2020
issues: write # for rustsec/audit-check to create issues
2121
runs-on: ubuntu-latest
2222
steps:
23-
- uses: actions/checkout@v4
23+
- uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5
2424

2525
- name: Generate Cargo.lock
2626
# https://github.com/rustsec/audit-check/issues/27
2727
run: cargo generate-lockfile --ignore-rust-version
2828

2929
- name: Audit Check
3030
# https://github.com/rustsec/audit-check/issues/2
31-
uses: rustsec/audit-check@master
31+
uses: rustsec/audit-check@858dc40f52ca2b8570b7a997c1c4e35c6fc9a432 # master
3232
with:
3333
token: ${{ secrets.GITHUB_TOKEN }}

.github/workflows/build.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ jobs:
1515
if: github.event_name == 'push' || github.event.pull_request.head.repo.full_name != github.repository
1616
steps:
1717
- name: Checkout sources
18-
uses: actions/checkout@v4
18+
uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5
1919
with:
2020
submodules: "recursive"
2121

@@ -30,7 +30,7 @@ jobs:
3030
sudo apt install -y openresty --no-install-recommends
3131
3232
- name: Install toolchain
33-
uses: dtolnay/rust-toolchain@master
33+
uses: dtolnay/rust-toolchain@3c5f7ea28cd621ae0bf5283f0e981fb97b8a7af9 # master
3434
with:
3535
toolchain: ${{ matrix.toolchain }}
3636
components: rustfmt, clippy

.github/workflows/docs.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ jobs:
1010
runs-on: ubuntu-latest
1111
steps:
1212
- name: Checkout sources
13-
uses: actions/checkout@v4
13+
uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5
1414
with:
1515
submodules: "recursive"
1616

@@ -20,7 +20,7 @@ jobs:
2020
sudo apt install -y cmake libclang-dev
2121
2222
- name: Install stable toolchain
23-
uses: dtolnay/rust-toolchain@stable
23+
uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
2424

2525
- name: Run cargo doc
2626
run: cargo doc --no-deps --all-features

.github/workflows/mark-stale.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ jobs:
1212
stale:
1313
runs-on: ubuntu-latest
1414
steps:
15-
- uses: actions/stale@v9
15+
- uses: actions/stale@5bef64f19d7facfb25b37b414482c7164d639639 # v9
1616
with:
1717
stale-issue-message: 'This question has been stale for a week. It will be closed in an additional day if not updated.'
1818
close-issue-message: 'This issue has been closed because it has been stalled with no activity.'

.github/workflows/semgrep.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -16,11 +16,11 @@ jobs:
1616
name: semgrep-oss
1717
runs-on: ubuntu-slim
1818
steps:
19-
- uses: actions/checkout@v5
19+
- uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5
2020
with:
2121
fetch-depth: 1
2222
- id: cache-semgrep
23-
uses: actions/cache@v5
23+
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5
2424
with:
2525
path: ~/.local
2626
key: semgrep-1.160.0-${{ runner.os }}

0 commit comments

Comments
 (0)