Skip to content

Commit 4d4fe97

Browse files
authored
ci: Pin all gh actions to commit SHAs (#108)
1 parent 7da3991 commit 4d4fe97

2 files changed

Lines changed: 14 additions & 14 deletions

File tree

.github/workflows/cd.yml

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -17,10 +17,10 @@ jobs:
1717

1818
steps:
1919
- name: Checkout
20-
uses: actions/checkout@v4
20+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
2121

2222
- name: Set up JDK 17
23-
uses: actions/setup-java@v3
23+
uses: actions/setup-java@17f84c3641ba7b8f6deff6309fc4c864478f5d62 # v3.14.1
2424
with:
2525
java-version: '17'
2626
distribution: 'temurin'
@@ -29,27 +29,27 @@ jobs:
2929
run: echo "api.version=1.44" > $HOME/.docker-java.properties
3030

3131
- name: Build
32-
uses: gradle/gradle-build-action@v2
32+
uses: gradle/gradle-build-action@a8f75513eafdebd8141bd1cd4e30fcd194af8dfa # v2.12.0
3333
with:
3434
gradle-version: 8.5
3535
arguments: build
3636

3737
- name: Test
38-
uses: gradle/gradle-build-action@v2
38+
uses: gradle/gradle-build-action@a8f75513eafdebd8141bd1cd4e30fcd194af8dfa # v2.12.0
3939
with:
4040
gradle-version: 8.5
4141
arguments: test --info
4242

4343
- name: Test Results
44-
uses: mikepenz/action-junit-report@v4
44+
uses: mikepenz/action-junit-report@db71d41eb79864e25ab0337e395c352e84523afe # v4.3.1
4545
if: always()
4646
with:
4747
fail_on_failure: true
4848
require_tests: true
4949
report_paths: '**/build/test-results/test/TEST-*.xml'
5050

5151
- name: Upload Jars
52-
uses: actions/upload-artifact@v4
52+
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
5353
with:
5454
name: QdrantJava
5555
path: build/libs
@@ -65,10 +65,10 @@ jobs:
6565
ORG_GRADLE_PROJECT_sonatypePassword: ${{ secrets.ORG_GRADLE_PROJECT_SONATYPEPASSWORD }}
6666
steps:
6767
- name: Checkout
68-
uses: actions/checkout@v4
68+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
6969

7070
- name: Set up JDK 17
71-
uses: actions/setup-java@v3
71+
uses: actions/setup-java@17f84c3641ba7b8f6deff6309fc4c864478f5d62 # v3.14.1
7272
with:
7373
java-version: '17'
7474
distribution: 'temurin'
@@ -77,13 +77,13 @@ jobs:
7777
run: echo "api.version=1.44" > $HOME/.docker-java.properties
7878

7979
- name: Publish package
80-
uses: gradle/gradle-build-action@v2
80+
uses: gradle/gradle-build-action@a8f75513eafdebd8141bd1cd4e30fcd194af8dfa # v2.12.0
8181
with:
8282
gradle-version: 8.5
8383
arguments: publishToSonatype closeAndReleaseSonatypeStagingRepository
8484

8585
- name: Deploy javadoc to Github Pages
86-
uses: dev-vince/actions-publish-javadoc@v1.0.1
86+
uses: dev-vince/actions-publish-javadoc@4004c6ca5881690e83c49a28a0b16fcab089e860 # v1.0.1
8787
with:
8888
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
8989
java-version: "17"

.github/workflows/test.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -19,10 +19,10 @@ jobs:
1919

2020
steps:
2121
- name: Checkout
22-
uses: actions/checkout@v4
22+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
2323

2424
- name: Set up JDK 17
25-
uses: actions/setup-java@v3
25+
uses: actions/setup-java@17f84c3641ba7b8f6deff6309fc4c864478f5d62 # v3.14.1
2626
with:
2727
java-version: '17'
2828
distribution: 'temurin'
@@ -31,13 +31,13 @@ jobs:
3131
run: echo "api.version=1.44" > $HOME/.docker-java.properties
3232

3333
- name: Build
34-
uses: gradle/gradle-build-action@v2
34+
uses: gradle/gradle-build-action@a8f75513eafdebd8141bd1cd4e30fcd194af8dfa # v2.12.0
3535
with:
3636
gradle-version: 8.5
3737
arguments: build --info
3838

3939
- name: Test
40-
uses: gradle/gradle-build-action@v2
40+
uses: gradle/gradle-build-action@a8f75513eafdebd8141bd1cd4e30fcd194af8dfa # v2.12.0
4141
with:
4242
gradle-version: 8.5
4343
arguments: test --info

0 commit comments

Comments
 (0)