Skip to content

Commit 8fbc2c5

Browse files
committed
Update GitHub Actions in .github/workflows/build-release.yml to use pinned hashes
1 parent 50c7dc8 commit 8fbc2c5

File tree

1 file changed

+8
-8
lines changed

1 file changed

+8
-8
lines changed

.github/workflows/build-release.yml

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ jobs:
3131
needs: [build_binaries]
3232
runs-on: ubuntu-latest
3333
steps:
34-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
34+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
3535
with:
3636
fetch-depth: 100
3737
ref: ${{ github.sha }}
@@ -52,11 +52,11 @@ jobs:
5252
5353
# download build artifacts
5454
- name: "Download build artifacts"
55-
uses: actions/download-artifact@cc203385981b70ca67e1cc392babf9cc229d5806 # v4
55+
uses: actions/download-artifact@cc203385981b70ca67e1cc392babf9cc229d5806 # v4.1.9
5656

5757
# create draft release
5858
- name: Create latest release
59-
uses: actions/create-release@0cb9c9b65d5d1901c1f53e5e66eaf4afd303e70e # v1
59+
uses: actions/create-release@0cb9c9b65d5d1901c1f53e5e66eaf4afd303e70e # v1.1.4
6060
id: create_release
6161
with:
6262
draft: true
@@ -85,7 +85,7 @@ jobs:
8585
cd assertoor_windows_amd64
8686
zip -r -q ../assertoor_${{ inputs.version }}_windows_amd64.zip .
8787
- name: "Upload release artifact: assertoor_${{ inputs.version }}_windows_amd64.zip"
88-
uses: actions/upload-release-asset@e8f9f06c4b078e705bd2ea027f0926603fc9b4d5 # v1
88+
uses: actions/upload-release-asset@e8f9f06c4b078e705bd2ea027f0926603fc9b4d5 # v1.0.2
8989
with:
9090
upload_url: ${{ steps.create_release.outputs.upload_url }}
9191
asset_path: ./assertoor_${{ inputs.version }}_windows_amd64.zip
@@ -99,7 +99,7 @@ jobs:
9999
cd assertoor_linux_amd64
100100
tar -czf ../assertoor_${{ inputs.version }}_linux_amd64.tar.gz .
101101
- name: "Upload release artifact: assertoor_${{ inputs.version }}_linux_amd64.tar.gz"
102-
uses: actions/upload-release-asset@e8f9f06c4b078e705bd2ea027f0926603fc9b4d5 # v1
102+
uses: actions/upload-release-asset@e8f9f06c4b078e705bd2ea027f0926603fc9b4d5 # v1.0.2
103103
with:
104104
upload_url: ${{ steps.create_release.outputs.upload_url }}
105105
asset_path: ./assertoor_${{ inputs.version }}_linux_amd64.tar.gz
@@ -113,7 +113,7 @@ jobs:
113113
cd assertoor_linux_arm64
114114
tar -czf ../assertoor_${{ inputs.version }}_linux_arm64.tar.gz .
115115
- name: "Upload release artifact: assertoor_${{ inputs.version }}_linux_arm64.tar.gz"
116-
uses: actions/upload-release-asset@e8f9f06c4b078e705bd2ea027f0926603fc9b4d5 # v1
116+
uses: actions/upload-release-asset@e8f9f06c4b078e705bd2ea027f0926603fc9b4d5 # v1.0.2
117117
with:
118118
upload_url: ${{ steps.create_release.outputs.upload_url }}
119119
asset_path: ./assertoor_${{ inputs.version }}_linux_arm64.tar.gz
@@ -127,7 +127,7 @@ jobs:
127127
cd assertoor_darwin_amd64
128128
tar -czf ../assertoor_${{ inputs.version }}_darwin_amd64.tar.gz .
129129
- name: "Upload release artifact: assertoor_${{ inputs.version }}_darwin_amd64.tar.gz"
130-
uses: actions/upload-release-asset@e8f9f06c4b078e705bd2ea027f0926603fc9b4d5 # v1
130+
uses: actions/upload-release-asset@e8f9f06c4b078e705bd2ea027f0926603fc9b4d5 # v1.0.2
131131
with:
132132
upload_url: ${{ steps.create_release.outputs.upload_url }}
133133
asset_path: ./assertoor_${{ inputs.version }}_darwin_amd64.tar.gz
@@ -141,7 +141,7 @@ jobs:
141141
cd assertoor_darwin_arm64
142142
tar -czf ../assertoor_${{ inputs.version }}_darwin_arm64.tar.gz .
143143
- name: "Upload release artifact: assertoor_${{ inputs.version }}_darwin_arm64.tar.gz"
144-
uses: actions/upload-release-asset@e8f9f06c4b078e705bd2ea027f0926603fc9b4d5 # v1
144+
uses: actions/upload-release-asset@e8f9f06c4b078e705bd2ea027f0926603fc9b4d5 # v1.0.2
145145
with:
146146
upload_url: ${{ steps.create_release.outputs.upload_url }}
147147
asset_path: ./assertoor_${{ inputs.version }}_darwin_arm64.tar.gz

0 commit comments

Comments
 (0)