Skip to content

Commit f4a9434

Browse files
committed
GHA: pin Actions to hash, bump to latest
Closes #417 Closes #418
1 parent 7dcfeb4 commit f4a9434

File tree

4 files changed

+15
-15
lines changed

4 files changed

+15
-15
lines changed

.github/workflows/build.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,7 @@ jobs:
4848
sudo apt-get -o Dpkg::Use-Pty=0 install \
4949
libcurl4-openssl-dev ${MATRIX_PACKAGES}
5050
51-
- uses: actions/checkout@v5
51+
- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
5252
with:
5353
persist-credentials: false
5454

@@ -100,7 +100,7 @@ jobs:
100100
work-vol: 'D:'
101101
packages: gcc-core make cmake libcurl-devel python3
102102

103-
- uses: actions/checkout@v5
103+
- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
104104
with:
105105
persist-credentials: false
106106

@@ -155,7 +155,7 @@ jobs:
155155
runs-on: macos-latest
156156

157157
steps:
158-
- uses: actions/checkout@v5
158+
- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
159159
with:
160160
persist-credentials: false
161161

@@ -190,7 +190,7 @@ jobs:
190190
run:
191191
shell: bash
192192
steps:
193-
- uses: actions/checkout@v5
193+
- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
194194
with:
195195
persist-credentials: false
196196

.github/workflows/checksrc.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ jobs:
2323
name: 'checksrc'
2424
runs-on: ubuntu-latest
2525
steps:
26-
- uses: actions/checkout@v5
26+
- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
2727
with:
2828
persist-credentials: false
2929

@@ -34,7 +34,7 @@ jobs:
3434
name: 'dist'
3535
runs-on: ubuntu-latest
3636
steps:
37-
- uses: actions/checkout@v5
37+
- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
3838
with:
3939
persist-credentials: false
4040

@@ -47,7 +47,7 @@ jobs:
4747
name: 'spellcheck, linters, REUSE'
4848
runs-on: ubuntu-latest
4949
steps:
50-
- uses: actions/checkout@v5
50+
- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
5151
with:
5252
persist-credentials: false
5353

.github/workflows/codeql.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -29,18 +29,18 @@ jobs:
2929
permissions:
3030
security-events: write # To create/update security events
3131
steps:
32-
- uses: actions/checkout@v5
32+
- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
3333
with:
3434
persist-credentials: false
3535

3636
- name: 'initialize'
37-
uses: github/codeql-action/init@v4
37+
uses: github/codeql-action/init@5d4e8d1aca955e8d8589aabd499c5cae939e33c7 # v4.31.9
3838
with:
3939
languages: actions, python
4040
queries: security-extended
4141

4242
- name: 'perform analysis'
43-
uses: github/codeql-action/analyze@v4
43+
uses: github/codeql-action/analyze@5d4e8d1aca955e8d8589aabd499c5cae939e33c7 # v4.31.9
4444

4545
c:
4646
if: ${{ github.repository_owner == 'curl' || github.event_name != 'schedule' }}
@@ -50,12 +50,12 @@ jobs:
5050
security-events: write # To create/update security events
5151

5252
steps:
53-
- uses: actions/checkout@v5
53+
- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
5454
with:
5555
persist-credentials: false
5656

5757
- name: 'initialize'
58-
uses: github/codeql-action/init@v4
58+
uses: github/codeql-action/init@5d4e8d1aca955e8d8589aabd499c5cae939e33c7 # v4.31.9
5959
with:
6060
languages: cpp
6161
build-mode: manual
@@ -76,4 +76,4 @@ jobs:
7676
cmake --build bld
7777
7878
- name: 'perform analysis'
79-
uses: github/codeql-action/analyze@v4
79+
uses: github/codeql-action/analyze@5d4e8d1aca955e8d8589aabd499c5cae939e33c7 # v4.31.9

.github/workflows/curl-for-win.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,7 @@ jobs:
2929
name: 'Windows llvm (arm64, x64)'
3030
runs-on: ubuntu-latest
3131
steps:
32-
- uses: actions/checkout@v5
32+
- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
3333
with:
3434
persist-credentials: false
3535
path: 'trurl'
@@ -56,7 +56,7 @@ jobs:
5656
5757
- name: 'list dependencies'
5858
run: cat urls.txt
59-
- uses: actions/upload-artifact@v4
59+
- uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6.0.0
6060
with:
6161
name: 'trurl-windows'
6262
retention-days: 5

0 commit comments

Comments
 (0)