Skip to content

Commit 5a7d504

Browse files
committed
chore: ci security
1 parent 7a4b6b5 commit 5a7d504

8 files changed

Lines changed: 42 additions & 42 deletions

.github/workflows/ci.yml

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -7,11 +7,11 @@ jobs:
77
build:
88
runs-on: ubuntu-latest
99
steps:
10-
- uses: actions/checkout@v6
10+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # was: actions/checkout@v6.0.2.0.2
1111

12-
- uses: pnpm/action-setup@v6
12+
- uses: pnpm/action-setup@0e279bb959325dab635dd2c09392533439d90093 # was: pnpm/action-setup@v6.0.8.0.8
1313

14-
- uses: actions/setup-node@v6
14+
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # was: actions/setup-node@v6.4.0.4.0
1515
with:
1616
node-version-file: .node-version
1717
cache: pnpm
@@ -23,11 +23,11 @@ jobs:
2323
lint:
2424
runs-on: ubuntu-latest
2525
steps:
26-
- uses: actions/checkout@v6
26+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # was: actions/checkout@v6.0.2
2727

28-
- uses: pnpm/action-setup@v6
28+
- uses: pnpm/action-setup@0e279bb959325dab635dd2c09392533439d90093 # was: pnpm/action-setup@v6.0.8
2929

30-
- uses: actions/setup-node@v6
30+
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # was: actions/setup-node@v6.4.0
3131
with:
3232
node-version-file: .node-version
3333
cache: pnpm
@@ -41,11 +41,11 @@ jobs:
4141
test:
4242
runs-on: ubuntu-latest
4343
steps:
44-
- uses: actions/checkout@v6
44+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # was: actions/checkout@v6.0.2
4545

46-
- uses: pnpm/action-setup@v6
46+
- uses: pnpm/action-setup@0e279bb959325dab635dd2c09392533439d90093 # was: pnpm/action-setup@v6.0.8
4747

48-
- uses: actions/setup-node@v6
48+
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # was: actions/setup-node@v6.4.0
4949
with:
5050
node-version-file: .node-version
5151
cache: pnpm

.github/workflows/reusable-pr-preview.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ jobs:
1414
github.event.workflow_run.conclusion == 'success'
1515
steps:
1616
- name: download pr artifact
17-
uses: dawidd6/action-download-artifact@v21
17+
uses: dawidd6/action-download-artifact@b6e2e70617bc3265edd6dab6c906732b2f1ae151 # was: dawidd6/action-download-artifact@v21
1818
with:
1919
workflow: ${{ github.event.workflow_run.workflow_id }}
2020
run_id: ${{ github.event.workflow_run.id }}
@@ -23,7 +23,7 @@ jobs:
2323
id: pr
2424
run: echo "id=$(<pr-id.txt)" >> $GITHUB_OUTPUT
2525
- name: download _site artifact
26-
uses: dawidd6/action-download-artifact@v21
26+
uses: dawidd6/action-download-artifact@b6e2e70617bc3265edd6dab6c906732b2f1ae151 # was: dawidd6/action-download-artifact@v21
2727
with:
2828
workflow: ${{ github.event.workflow_run.workflow_id }}
2929
run_id: ${{ github.event.workflow_run.id }}
@@ -72,7 +72,7 @@ jobs:
7272
github.event.workflow_run.conclusion == 'failure'
7373
steps:
7474
- name: download pr artifact
75-
uses: dawidd6/action-download-artifact@v21
75+
uses: dawidd6/action-download-artifact@b6e2e70617bc3265edd6dab6c906732b2f1ae151 # was: dawidd6/action-download-artifact@v21
7676
with:
7777
workflow: ${{ github.event.workflow_run.workflow_id }}
7878
run_id: ${{ github.event.workflow_run.id }}

.github/workflows/reusable-publish-npm.yml

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -54,11 +54,11 @@ jobs:
5454
runs-on: ubuntu-latest
5555
if: github.event.ref_type == 'tag' && !inputs.publish-npm
5656
steps:
57-
- uses: actions/checkout@v6.0.2
57+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # was: actions/checkout@v6.0.2
5858
with:
5959
submodules: recursive
6060

61-
- uses: actions/setup-node@v6.4.0
61+
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # was: actions/setup-node@v6.4.0
6262
with:
6363
node-version: ${{ inputs.node-version-file == '' && inputs.node-version || null }}
6464
node-version-file: ${{ inputs.node-version-file != '' && inputs.node-version-file || null }}
@@ -67,7 +67,7 @@ jobs:
6767

6868
- run: ${{ inputs.package-manager }} run build
6969

70-
- uses: actions/setup-node@v6.4.0
70+
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # was: actions/setup-node@v6.4.0
7171
with:
7272
node-version: 24
7373

@@ -79,7 +79,7 @@ jobs:
7979
8080
- name: npm publish
8181
if: ${{ inputs.package-manager == 'npm'}}
82-
uses: JS-DevTools/npm-publish@v4
82+
uses: JS-DevTools/npm-publish@0fd2f4369c5d6bcfcde6091a7c527d810b9b5c3f # was: JS-DevTools/npm-publish@v4
8383
with:
8484
tag: ${{ steps.tag.outputs.tag }}
8585

@@ -91,14 +91,14 @@ jobs:
9191
runs-on: ubuntu-latest
9292
if: github.event.ref_type == 'tag' && !inputs.publish-tag-website
9393
steps:
94-
- uses: actions/checkout@v6.0.2
94+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # was: actions/checkout@v6.0.2
9595
with:
9696
submodules: recursive
9797

98-
- uses: pnpm/action-setup@v6.0.8
98+
- uses: pnpm/action-setup@0e279bb959325dab635dd2c09392533439d90093 # was: pnpm/action-setup@v6.0.8
9999
if: ${{ inputs.package-manager == 'pnpm' }}
100100

101-
- uses: actions/setup-node@v6.4.0
101+
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # was: actions/setup-node@v6.4.0
102102
with:
103103
node-version: ${{ inputs.node-version-file == '' && inputs.node-version || null }}
104104
node-version-file: ${{ inputs.node-version-file != '' && inputs.node-version-file || null }}
@@ -126,7 +126,7 @@ jobs:
126126
runs-on: ubuntu-latest
127127
if: github.event.ref_type == 'tag' && !inputs.publish-official-website
128128
steps:
129-
- uses: actions/checkout@v6.0.2
129+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # was: actions/checkout@v6.0.2
130130
with:
131131
ref: main
132132
fetch-depth: 0

.github/workflows/reusable-spell-check.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,9 +12,9 @@ jobs:
1212
name: Typos
1313
runs-on: ubuntu-latest
1414
steps:
15-
- uses: actions/checkout@v6.0.2
15+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # was: actions/checkout@v6.0.2
1616

1717
- name: Check spelling
18-
uses: crate-ci/typos@v1.46.1
18+
uses: crate-ci/typos@5374cbf686e897b15713110e233094e2874de7ef # was: crate-ci/typos@v1.46.1
1919
with:
2020
config: ${{ inputs.config }}

.github/workflows/reusable-unit-test.yml

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -28,14 +28,14 @@ jobs:
2828
test:
2929
runs-on: ubuntu-latest
3030
steps:
31-
- uses: actions/checkout@v6.0.2
31+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # was: actions/checkout@v6.0.2
3232
with:
3333
submodules: recursive
3434

35-
- uses: pnpm/action-setup@v6.0.8
35+
- uses: pnpm/action-setup@0e279bb959325dab635dd2c09392533439d90093 # was: pnpm/action-setup@v6.0.8
3636
if: ${{ inputs.package-manager == 'pnpm' }}
3737

38-
- uses: actions/setup-node@v6.4.0
38+
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # was: actions/setup-node@v6.4.0
3939
with:
4040
node-version: ${{ inputs.node-version-file == '' && inputs.node-version || null }}
4141
node-version-file: ${{ inputs.node-version-file != '' && inputs.node-version-file || null }}
@@ -45,22 +45,22 @@ jobs:
4545
- run: ${{ inputs.package-manager }} run lint
4646
- run: ${{ inputs.package-manager }} run test
4747
# upload report to codecov
48-
- uses: codecov/codecov-action@v6.0.0
48+
- uses: codecov/codecov-action@57e3a136b779b570ffcdbf80b3bdc90e7fab3de2 # was: codecov/codecov-action@v6.0.0
4949
with:
5050
token: ${{ secrets.CODECOV_TOKEN }}
5151

5252
site:
5353
if: ${{ !inputs.skip-site }}
5454
runs-on: ubuntu-latest
5555
steps:
56-
- uses: actions/checkout@v6.0.2
56+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # was: actions/checkout@v6.0.2
5757
with:
5858
submodules: recursive
5959

60-
- uses: pnpm/action-setup@v6.0.8
60+
- uses: pnpm/action-setup@0e279bb959325dab635dd2c09392533439d90093 # was: pnpm/action-setup@v6.0.8
6161
if: ${{ inputs.package-manager == 'pnpm' }}
6262

63-
- uses: actions/setup-node@v6.4.0
63+
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # was: actions/setup-node@v6.4.0
6464
with:
6565
node-version: ${{ inputs.node-version-file == '' && inputs.node-version || null }}
6666
node-version-file: ${{ inputs.node-version-file != '' && inputs.node-version-file || null }}
@@ -74,7 +74,7 @@ jobs:
7474
zip -r _site.zip _site
7575
7676
- name: upload _site artifact
77-
uses: actions/upload-artifact@v7.0.1
77+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # was: actions/upload-artifact@v7.0.1
7878
with:
7979
name: _site
8080
path: _site.zip
@@ -86,22 +86,22 @@ jobs:
8686

8787
- name: Upload PR number
8888
if: ${{ always() }}
89-
uses: actions/upload-artifact@v7.0.1
89+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # was: actions/upload-artifact@v7.0.1
9090
with:
9191
name: pr
9292
path: ./pr-id.txt
9393

9494
build:
9595
runs-on: ubuntu-latest
9696
steps:
97-
- uses: actions/checkout@v6.0.2
97+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # was: actions/checkout@v6.0.2
9898
with:
9999
submodules: recursive
100100

101-
- uses: pnpm/action-setup@v6.0.8
101+
- uses: pnpm/action-setup@0e279bb959325dab635dd2c09392533439d90093 # was: pnpm/action-setup@v6.0.8
102102
if: ${{ inputs.package-manager == 'pnpm' }}
103103

104-
- uses: actions/setup-node@v6.4.0
104+
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # was: actions/setup-node@v6.4.0
105105
with:
106106
node-version: ${{ inputs.node-version-file == '' && inputs.node-version || null }}
107107
node-version-file: ${{ inputs.node-version-file != '' && inputs.node-version-file || null }}

.github/workflows/spell-check.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,9 +11,9 @@ jobs:
1111
name: Typos
1212
runs-on: ubuntu-latest
1313
steps:
14-
- uses: actions/checkout@v6.0.2
14+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # was: actions/checkout@v6.0.2
1515

1616
- name: Check spelling
17-
uses: crate-ci/typos@v1.46.1
17+
uses: crate-ci/typos@5374cbf686e897b15713110e233094e2874de7ef # was: crate-ci/typos@v1.46.1
1818
with:
1919
config: ${{ inputs.config }}

.github/workflows/test-close-release-issue.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ jobs:
1111
name: test
1212
runs-on: ubuntu-latest
1313
steps:
14-
- uses: actions/checkout@v6.0.2
14+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # was: actions/checkout@v6.0.2
1515

1616
- name: test
1717
uses: ./actions/close-release-issue

.github/workflows/test-upgrade-deps.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -11,9 +11,9 @@ jobs:
1111
name: tdesign-vue
1212
runs-on: ubuntu-latest
1313
steps:
14-
- uses: actions/checkout@v6.0.2
14+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # was: actions/checkout@v6.0.2
1515

16-
- uses: actions/setup-node@v6.4.0
16+
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # was: actions/setup-node@v6.4.0
1717

1818
- name: test
1919
uses: ./actions/upgrade-deps
@@ -30,9 +30,9 @@ jobs:
3030
name: tdesign-vue-next
3131
runs-on: ubuntu-latest
3232
steps:
33-
- uses: actions/checkout@v6.0.2
33+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # was: actions/checkout@v6.0.2
3434

35-
- uses: actions/setup-node@v6.4.0
35+
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # was: actions/setup-node@v6.4.0
3636

3737
- name: test
3838
uses: ./actions/upgrade-deps
@@ -51,7 +51,7 @@ jobs:
5151
# name: tdesign-flutter
5252
# runs-on: ubuntu-latest
5353
# steps:
54-
# - uses: actions/checkout@v6.0.2
54+
# - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # was: actions/checkout@v6.0.2
5555

5656
# - uses: actions/setup-node@v6.3.0
5757
# with:

0 commit comments

Comments
 (0)