Skip to content

Commit a524ac7

Browse files
chore(deps): pin trusted workflows based on HashiCorp TSCCR (#3770)
Bumping GitHub Actions version to latest TSCCR release. * changes in `.github/workflows/build.yml` - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) - bump `actions/cache` from `v4.1.1` to `v4.1.2` ([release notes](https://github.com/actions/cache/releases/tag/v4.1.2)) - bump `actions/cache` from `v4.1.1` to `v4.1.2` ([release notes](https://github.com/actions/cache/releases/tag/v4.1.2)) * changes in `.github/workflows/docker.yml` - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) - bump `actions/cache` from `v4.1.1` to `v4.1.2` ([release notes](https://github.com/actions/cache/releases/tag/v4.1.2)) * changes in `.github/workflows/examples.yml` - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) - bump `actions/cache` from `v4.1.1` to `v4.1.2` ([release notes](https://github.com/actions/cache/releases/tag/v4.1.2)) - bump `actions/cache` from `v4.1.1` to `v4.1.2` ([release notes](https://github.com/actions/cache/releases/tag/v4.1.2)) - bump `actions/cache` from `v4.1.1` to `v4.1.2` ([release notes](https://github.com/actions/cache/releases/tag/v4.1.2)) * changes in `.github/workflows/integration.yml` - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) - bump `actions/cache` from `v4.1.1` to `v4.1.2` ([release notes](https://github.com/actions/cache/releases/tag/v4.1.2)) - bump `actions/cache` from `v4.1.1` to `v4.1.2` ([release notes](https://github.com/actions/cache/releases/tag/v4.1.2)) - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) - bump `actions/cache/restore` from `v4.1.1` to `v4.1.2` ([release notes](https://github.com/actions/cache/releases/tag/v4.1.2)) - bump `actions/cache` from `v4.1.1` to `v4.1.2` ([release notes](https://github.com/actions/cache/releases/tag/v4.1.2)) - bump `actions/cache` from `v4.1.1` to `v4.1.2` ([release notes](https://github.com/actions/cache/releases/tag/v4.1.2)) - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) - bump `actions/cache/restore` from `v4.1.1` to `v4.1.2` ([release notes](https://github.com/actions/cache/releases/tag/v4.1.2)) - bump `actions/cache` from `v4.1.1` to `v4.1.2` ([release notes](https://github.com/actions/cache/releases/tag/v4.1.2)) - bump `actions/cache` from `v4.1.1` to `v4.1.2` ([release notes](https://github.com/actions/cache/releases/tag/v4.1.2)) - bump `actions/setup-go` from `v5.0.2` to `v5.1.0` ([release notes](https://github.com/actions/setup-go/releases/tag/v5.1.0)) * changes in `.github/workflows/linting.yml` - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) * changes in `.github/workflows/pr-copyright.yml` - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) * changes in `.github/workflows/pr-depcheck.yml` - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) * changes in `.github/workflows/provider-integration.yml` - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) - bump `actions/cache` from `v4.1.1` to `v4.1.2` ([release notes](https://github.com/actions/cache/releases/tag/v4.1.2)) - bump `actions/cache` from `v4.1.1` to `v4.1.2` ([release notes](https://github.com/actions/cache/releases/tag/v4.1.2)) - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) - bump `actions/cache/restore` from `v4.1.1` to `v4.1.2` ([release notes](https://github.com/actions/cache/releases/tag/v4.1.2)) - bump `actions/cache` from `v4.1.1` to `v4.1.2` ([release notes](https://github.com/actions/cache/releases/tag/v4.1.2)) - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) - bump `actions/setup-go` from `v5.0.2` to `v5.1.0` ([release notes](https://github.com/actions/setup-go/releases/tag/v5.1.0)) - bump `actions/cache/restore` from `v4.1.1` to `v4.1.2` ([release notes](https://github.com/actions/cache/releases/tag/v4.1.2)) - bump `actions/cache` from `v4.1.1` to `v4.1.2` ([release notes](https://github.com/actions/cache/releases/tag/v4.1.2)) * changes in `.github/workflows/registry-docs-pr-based.yml` - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) - bump `actions/setup-node` from `v4.0.4` to `v4.1.0` ([release notes](https://github.com/actions/setup-node/releases/tag/v4.1.0)) - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) - bump `actions/setup-node` from `v4.0.4` to `v4.1.0` ([release notes](https://github.com/actions/setup-node/releases/tag/v4.1.0)) - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) * changes in `.github/workflows/release.yml` - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) * changes in `.github/workflows/release_next.yml` - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) * changes in `.github/workflows/unit.yml` - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) - bump `actions/cache` from `v4.1.1` to `v4.1.2` ([release notes](https://github.com/actions/cache/releases/tag/v4.1.2)) - bump `actions/cache` from `v4.1.1` to `v4.1.2` ([release notes](https://github.com/actions/cache/releases/tag/v4.1.2)) - bump `actions/cache` from `v4.1.1` to `v4.1.2` ([release notes](https://github.com/actions/cache/releases/tag/v4.1.2)) * changes in `.github/workflows/website-release.yml` - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) * changes in `.github/workflows/yarn-upgrade.yml` - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) - bump `actions/cache` from `v4.1.1` to `v4.1.2` ([release notes](https://github.com/actions/cache/releases/tag/v4.1.2)) - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) - bump `actions/cache` from `v4.1.1` to `v4.1.2` ([release notes](https://github.com/actions/cache/releases/tag/v4.1.2)) - bump `actions/checkout` from `v4.2.1` to `v4.2.2` ([release notes](https://github.com/actions/checkout/releases/tag/v4.2.2)) - bump `actions/cache` from `v4.1.1` to `v4.1.2` ([release notes](https://github.com/actions/cache/releases/tag/v4.1.2)) _This PR was auto-generated by [security-tsccr/actions/runs/11773085209](https://github.com/hashicorp/security-tsccr/actions/runs/11773085209)_ _You can alter the configuration of this automation via the hcl config in [security-tsccr/automation](https://github.com/hashicorp/security-tsccr/tree/main/automation)_ _This PR can be regenerated by dispatching the GitHub workflow [Pin Action Refs](https://github.com/hashicorp/security-tsccr/actions/workflows/pin-workflows.yml). Please reach out to #team-prodsec if you have any questions._ [](hashicorp/security-tsccr#193) Co-authored-by: hashicorp-tsccr[bot] <hashicorp-tsccr[bot]@users.noreply.github.com>
1 parent e7986f9 commit a524ac7

14 files changed

+60
-60
lines changed

.github/workflows/build.yml

+3-3
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ jobs:
2222
timeout-minutes: 60
2323

2424
steps:
25-
- uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
25+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
2626
- name: "Add Git safe.directory" # Go 1.18+ started embedding repo info in the build and e.g. building @cdktf/hcl2json fails without this
2727
run: git config --global --add safe.directory /__w/terraform-cdk/terraform-cdk
2828
- name: ensure correct user
@@ -34,14 +34,14 @@ jobs:
3434
echo "yarn=$(yarn cache dir)" >> $GITHUB_OUTPUT
3535
mkdir -p /usr/local/share/.cache/go
3636
echo "go=/usr/local/share/.cache/go" >> $GITHUB_OUTPUT
37-
- uses: actions/cache@3624ceb22c1c5a301c8db4169662070a689d9ea8 # v4.1.1
37+
- uses: actions/cache@6849a6489940f00c2f30c0fb92c6274307ccb58a # v4.1.2
3838
with:
3939
path: ${{ steps.global-cache-dir-path.outputs.yarn }}
4040
key: yarn-${{ runner.os }}-${{ hashFiles('**/yarn.lock') }}-build
4141
restore-keys: |
4242
yarn-${{ runner.os }}-${{ hashFiles('**/yarn.lock') }}-
4343
yarn-${{ runner.os }}-
44-
- uses: actions/cache@3624ceb22c1c5a301c8db4169662070a689d9ea8 # v4.1.1
44+
- uses: actions/cache@6849a6489940f00c2f30c0fb92c6274307ccb58a # v4.1.2
4545
with:
4646
path: ${{ steps.global-cache-dir-path.outputs.go }}
4747
key: go-${{ runner.os }}-${{ hashFiles('**/go.sum') }}-build

.github/workflows/docker.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -16,11 +16,11 @@ jobs:
1616
if: github.repository == 'hashicorp/terraform-cdk'
1717
runs-on: ubuntu-latest
1818
steps:
19-
- uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
19+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
2020
- name: Set up Docker Buildx
2121
uses: docker/setup-buildx-action@c47758b77c9736f4b2ef4073d4d51994fabfe349 # v3.7.1
2222
- name: Cache Docker layers
23-
uses: actions/cache@3624ceb22c1c5a301c8db4169662070a689d9ea8 # v4.1.1
23+
uses: actions/cache@6849a6489940f00c2f30c0fb92c6274307ccb58a # v4.1.2
2424
with:
2525
path: /tmp/.buildx-cache
2626
key: ${{ runner.os }}-buildx-${{ hashFiles('/Dockerfile', '.terraform.versions.json') }}

.github/workflows/examples.yml

+5-5
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ jobs:
2424
examples: ${{ steps.set-examples.outputs.examples }}
2525
steps:
2626
- name: Checkout
27-
uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
27+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
2828
- id: set-examples
2929
run: |
3030
tfDefault=$(cat .terraform.versions.json | jq -r '.default')
@@ -45,7 +45,7 @@ jobs:
4545
CHECKPOINT_DISABLE: "1"
4646
timeout-minutes: 60
4747
steps:
48-
- uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
48+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
4949
- name: "Add Git safe.directory" # Go 1.18+ started embedding repo info in the build and e.g. building @cdktf/hcl2json fails without this
5050
run: git config --global --add safe.directory /__w/terraform-cdk/terraform-cdk
5151
- name: ensure correct user
@@ -59,20 +59,20 @@ jobs:
5959
echo "terraform=/usr/local/share/.cache/terraform" >> $GITHUB_OUTPUT
6060
mkdir -p /usr/local/share/.cache/go
6161
echo "go=/usr/local/share/.cache/go" >> $GITHUB_OUTPUT
62-
- uses: actions/cache@3624ceb22c1c5a301c8db4169662070a689d9ea8 # v4.1.1
62+
- uses: actions/cache@6849a6489940f00c2f30c0fb92c6274307ccb58a # v4.1.2
6363
with:
6464
path: ${{ steps.global-cache-dir-path.outputs.yarn }}
6565
key: yarn-${{ runner.os }}-${{ hashFiles('**/yarn.lock') }}-examples
6666
restore-keys: |
6767
yarn-${{ runner.os }}-${{ hashFiles('**/yarn.lock') }}-
6868
yarn-${{ runner.os }}-
69-
- uses: actions/cache@3624ceb22c1c5a301c8db4169662070a689d9ea8 # v4.1.1
69+
- uses: actions/cache@6849a6489940f00c2f30c0fb92c6274307ccb58a # v4.1.2
7070
with:
7171
path: ${{ steps.global-cache-dir-path.outputs.terraform }}
7272
key: terraform-${{ runner.os }}-${{ matrix.terraform }}-examples
7373
restore-keys: |
7474
terraform-${{ runner.os }}-${{ matrix.terraform }}
75-
- uses: actions/cache@3624ceb22c1c5a301c8db4169662070a689d9ea8 # v4.1.1
75+
- uses: actions/cache@6849a6489940f00c2f30c0fb92c6274307ccb58a # v4.1.2
7676
with:
7777
path: ${{ steps.global-cache-dir-path.outputs.go }}
7878
key: go-${{ runner.os }}-${{ hashFiles('**/go.sum') }}-examples

.github/workflows/integration.yml

+12-12
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@ jobs:
2828
timeout-minutes: 60
2929

3030
steps:
31-
- uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
31+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
3232
- name: "Add Git safe.directory" # Go 1.18+ started embedding repo info in the build and e.g. building @cdktf/hcl2json fails without this
3333
run: git config --global --add safe.directory /__w/terraform-cdk/terraform-cdk
3434
- name: ensure correct user
@@ -40,14 +40,14 @@ jobs:
4040
echo "yarn=$(yarn cache dir)" >> $GITHUB_OUTPUT
4141
mkdir -p /usr/local/share/.cache/go
4242
echo "go=/usr/local/share/.cache/go" >> $GITHUB_OUTPUT
43-
- uses: actions/cache@3624ceb22c1c5a301c8db4169662070a689d9ea8 # v4.1.1
43+
- uses: actions/cache@6849a6489940f00c2f30c0fb92c6274307ccb58a # v4.1.2
4444
with:
4545
path: ${{ steps.global-cache-dir-path.outputs.yarn }}
4646
key: yarn-${{ runner.os }}-${{ hashFiles('**/yarn.lock') }}-integration
4747
restore-keys: |
4848
yarn-${{ runner.os }}-${{ hashFiles('**/yarn.lock') }}-
4949
yarn-${{ runner.os }}-
50-
- uses: actions/cache@3624ceb22c1c5a301c8db4169662070a689d9ea8 # v4.1.1
50+
- uses: actions/cache@6849a6489940f00c2f30c0fb92c6274307ccb58a # v4.1.2
5151
with:
5252
path: ${{ steps.global-cache-dir-path.outputs.go }}
5353
key: go-${{ runner.os }}-${{ hashFiles('**/go.sum') }}-integration
@@ -103,7 +103,7 @@ jobs:
103103
timeout-minutes: 60
104104

105105
steps:
106-
- uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
106+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
107107
- name: ensure correct user
108108
run: chown -R root /__w/terraform-cdk
109109
# Setup caches for yarn, terraform, and go
@@ -116,21 +116,21 @@ jobs:
116116
mkdir -p /usr/local/share/.cache/go
117117
echo "go=/usr/local/share/.cache/go" >> $GITHUB_OUTPUT
118118
# only restore as an individual cache as per matrix explodes our cache usage
119-
- uses: actions/cache/restore@3624ceb22c1c5a301c8db4169662070a689d9ea8 # v4.1.1
119+
- uses: actions/cache/restore@6849a6489940f00c2f30c0fb92c6274307ccb58a # v4.1.2
120120
with:
121121
path: ${{ steps.global-cache-dir-path.outputs.yarn }}
122122
key: yarn-${{ runner.os }}-${{ hashFiles('**/yarn.lock') }}-integration
123123
restore-keys: |
124124
yarn-${{ runner.os }}-${{ hashFiles('**/yarn.lock') }}-
125125
yarn-${{ runner.os }}-
126-
- uses: actions/cache@3624ceb22c1c5a301c8db4169662070a689d9ea8 # v4.1.1
126+
- uses: actions/cache@6849a6489940f00c2f30c0fb92c6274307ccb58a # v4.1.2
127127
with:
128128
path: ${{ steps.global-cache-dir-path.outputs.terraform }}
129129
# put matrix before integration to not restore caches from other sibling matrix jobs
130130
key: terraform-${{ runner.os }}-${{ matrix.terraform }}-matrix-integration-${{ matrix.target }}
131131
restore-keys: |
132132
terraform-${{ runner.os }}-${{ matrix.terraform }}-
133-
- uses: actions/cache@3624ceb22c1c5a301c8db4169662070a689d9ea8 # v4.1.1
133+
- uses: actions/cache@6849a6489940f00c2f30c0fb92c6274307ccb58a # v4.1.2
134134
with:
135135
path: ${{ steps.global-cache-dir-path.outputs.go }}
136136
# put matrix before integration to not restore caches from other sibling matrix jobs
@@ -176,7 +176,7 @@ jobs:
176176
timeout-minutes: 60
177177

178178
steps:
179-
- uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
179+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
180180
# Setup caches for yarn, terraform, and go
181181
- name: Get cache directory paths
182182
id: global-cache-dir-path
@@ -188,21 +188,21 @@ jobs:
188188
mkdir -p /usr/local/share/.cache/go
189189
echo "go=/usr/local/share/.cache/go" >> $GITHUB_OUTPUT
190190
# only restore as an individual cache as per matrix explodes our cache usage
191-
- uses: actions/cache/restore@3624ceb22c1c5a301c8db4169662070a689d9ea8 # v4.1.1
191+
- uses: actions/cache/restore@6849a6489940f00c2f30c0fb92c6274307ccb58a # v4.1.2
192192
with:
193193
path: ${{ steps.global-cache-dir-path.outputs.yarn }}
194194
key: yarn-${{ runner.os }}-${{ hashFiles('**/yarn.lock') }}-integration
195195
restore-keys: |
196196
yarn-${{ runner.os }}-${{ hashFiles('**/yarn.lock') }}-
197197
yarn-${{ runner.os }}-
198-
- uses: actions/cache@3624ceb22c1c5a301c8db4169662070a689d9ea8 # v4.1.1
198+
- uses: actions/cache@6849a6489940f00c2f30c0fb92c6274307ccb58a # v4.1.2
199199
with:
200200
path: ${{ steps.global-cache-dir-path.outputs.terraform }}
201201
# put matrix before integration to not restore caches from other sibling matrix jobs
202202
key: terraform-${{ runner.os }}-${{ matrix.terraform }}-matrix-integration-${{ matrix.target }}
203203
restore-keys: |
204204
terraform-${{ runner.os }}-${{ matrix.terraform }}-
205-
- uses: actions/cache@3624ceb22c1c5a301c8db4169662070a689d9ea8 # v4.1.1
205+
- uses: actions/cache@6849a6489940f00c2f30c0fb92c6274307ccb58a # v4.1.2
206206
with:
207207
path: ${{ steps.global-cache-dir-path.outputs.go }}
208208
# put matrix before integration to not restore caches from other sibling matrix jobs
@@ -219,7 +219,7 @@ jobs:
219219
- name: Install pipenv
220220
run: pip install pipenv
221221
- name: Install Go
222-
uses: actions/setup-go@0a12ed9d6a96ab950c8f026ed9f722fe0da7ef32 # v5.0.2
222+
uses: actions/setup-go@41dfa10bad2bb2ae585af6ee5bb4d7d973ad74ed # v5.1.0
223223
with:
224224
go-version: 1.18.x
225225
cache: false # This is disabled because we don't have a go.sum file and setup-go expects it to use caching. Thus, caching is always broken anyways

.github/workflows/linting.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ jobs:
2020
container:
2121
image: docker.mirror.hashicorp.services/hashicorp/jsii-terraform
2222
steps:
23-
- uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
23+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
2424
- name: installing dependencies
2525
run: |
2626
yarn install --frozen-lockfile
@@ -33,7 +33,7 @@ jobs:
3333
container:
3434
image: docker.mirror.hashicorp.services/hashicorp/jsii-terraform
3535
steps:
36-
- uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
36+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
3737
- name: installing dependencies
3838
run: |
3939
yarn install --frozen-lockfile

.github/workflows/pr-copyright.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ jobs:
1818
contents: write
1919
steps:
2020
- name: Checkout
21-
uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
21+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
2222
with:
2323
ref: ${{ github.event.pull_request.head.ref }}
2424
repository: ${{ github.event.pull_request.head.repo.full_name }}

.github/workflows/pr-depcheck.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@ jobs:
2828
]
2929

3030
steps:
31-
- uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
31+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
3232
- name: "Run Depcheck"
3333
run: |
3434
npx lerna exec --scope '${{ matrix.package }}' -- npx -y depcheck --ignores="@types/*,jsii,jsii-pacmak,jsii-docgen,yoga-layout-prebuilt,eslint,jest,tsc-files,typescript,esbuild,esbuild-jest,graphology-types"

.github/workflows/provider-integration.yml

+10-10
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,7 @@ jobs:
3333
timeout-minutes: 60
3434

3535
steps:
36-
- uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
36+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
3737
- name: "Add Git safe.directory" # Go 1.18+ started embedding repo info in the build and e.g. building @cdktf/hcl2json fails without this
3838
run: git config --global --add safe.directory /__w/terraform-cdk/terraform-cdk
3939
- name: ensure correct user
@@ -45,14 +45,14 @@ jobs:
4545
echo "yarn=$(yarn cache dir)" >> $GITHUB_OUTPUT
4646
mkdir -p /usr/local/share/.cache/go
4747
echo "go=/usr/local/share/.cache/go" >> $GITHUB_OUTPUT
48-
- uses: actions/cache@3624ceb22c1c5a301c8db4169662070a689d9ea8 # v4.1.1
48+
- uses: actions/cache@6849a6489940f00c2f30c0fb92c6274307ccb58a # v4.1.2
4949
with:
5050
path: ${{ steps.global-cache-dir-path.outputs.yarn }}
5151
key: yarn-${{ runner.os }}-${{ hashFiles('**/yarn.lock') }}-provider-integration
5252
restore-keys: |
5353
yarn-${{ runner.os }}-${{ hashFiles('**/yarn.lock') }}-
5454
yarn-${{ runner.os }}-
55-
- uses: actions/cache@3624ceb22c1c5a301c8db4169662070a689d9ea8 # v4.1.1
55+
- uses: actions/cache@6849a6489940f00c2f30c0fb92c6274307ccb58a # v4.1.2
5656
with:
5757
path: ${{ steps.global-cache-dir-path.outputs.go }}
5858
key: go-${{ runner.os }}-${{ hashFiles('**/go.sum') }}-provider-integration
@@ -96,7 +96,7 @@ jobs:
9696
timeout-minutes: 60
9797

9898
steps:
99-
- uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
99+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
100100
- name: Download dist
101101
uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4.1.8
102102
with:
@@ -111,14 +111,14 @@ jobs:
111111
mkdir -p /usr/local/share/.cache/terraform
112112
echo "terraform=/usr/local/share/.cache/terraform" >> $GITHUB_OUTPUT
113113
# Only restoring yarn caches as the dependencies are not indiviual to each matrix job
114-
- uses: actions/cache/restore@3624ceb22c1c5a301c8db4169662070a689d9ea8 # v4.1.1
114+
- uses: actions/cache/restore@6849a6489940f00c2f30c0fb92c6274307ccb58a # v4.1.2
115115
with:
116116
path: ${{ steps.global-cache-dir-path.outputs.yarn }}
117117
key: yarn-${{ runner.os }}-${{ hashFiles('**/yarn.lock') }}-provider-integration
118118
restore-keys: |
119119
yarn-${{ runner.os }}-${{ hashFiles('**/yarn.lock') }}-
120120
yarn-${{ runner.os }}-
121-
- uses: actions/cache@3624ceb22c1c5a301c8db4169662070a689d9ea8 # v4.1.1
121+
- uses: actions/cache@6849a6489940f00c2f30c0fb92c6274307ccb58a # v4.1.2
122122
with:
123123
path: ${{ steps.global-cache-dir-path.outputs.terraform }}
124124
# put matrix before provider-integration to not restore caches from other sibling matrix jobs
@@ -147,7 +147,7 @@ jobs:
147147
timeout-minutes: 60
148148

149149
steps:
150-
- uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
150+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
151151
- name: HashiCorp - Setup Terraform
152152
uses: hashicorp/setup-terraform@633666f66e0061ca3b725c73b2ec20cd13a8fdd1
153153
with:
@@ -156,7 +156,7 @@ jobs:
156156
- name: Install pipenv
157157
run: pip install pipenv
158158
- name: Install Go
159-
uses: actions/setup-go@0a12ed9d6a96ab950c8f026ed9f722fe0da7ef32 # v5.0.2
159+
uses: actions/setup-go@41dfa10bad2bb2ae585af6ee5bb4d7d973ad74ed # v5.1.0
160160
with:
161161
go-version: 1.16.x
162162
- name: Download dist
@@ -172,14 +172,14 @@ jobs:
172172
mkdir -p /usr/local/share/.cache/terraform
173173
echo "terraform=/usr/local/share/.cache/terraform" >> $GITHUB_OUTPUT
174174
# Only restoring yarn caches to save available cache storage size
175-
- uses: actions/cache/restore@3624ceb22c1c5a301c8db4169662070a689d9ea8 # v4.1.1
175+
- uses: actions/cache/restore@6849a6489940f00c2f30c0fb92c6274307ccb58a # v4.1.2
176176
with:
177177
path: ${{ steps.global-cache-dir-path.outputs.yarn }}
178178
key: yarn-${{ runner.os }}-${{ hashFiles('**/yarn.lock') }}-provider-integration
179179
restore-keys: |
180180
yarn-${{ runner.os }}-${{ hashFiles('**/yarn.lock') }}-
181181
yarn-${{ runner.os }}-
182-
- uses: actions/cache@3624ceb22c1c5a301c8db4169662070a689d9ea8 # v4.1.1
182+
- uses: actions/cache@6849a6489940f00c2f30c0fb92c6274307ccb58a # v4.1.2
183183
with:
184184
path: ${{ steps.global-cache-dir-path.outputs.terraform }}
185185
# put matrix before provider-integration to not restore caches from other sibling matrix jobs

.github/workflows/registry-docs-pr-based.yml

+7-7
Original file line numberDiff line numberDiff line change
@@ -69,7 +69,7 @@ jobs:
6969
cdktfDocsCleanupBranches:
7070
runs-on: ubuntu-latest
7171
steps:
72-
- uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
72+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
7373
with:
7474
repository: ${{ inputs.repository }}
7575
ref: ${{ inputs.branch }}
@@ -88,7 +88,7 @@ jobs:
8888
needs:
8989
- cdktfDocsCleanupBranches
9090
steps:
91-
- uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
91+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
9292
with:
9393
repository: ${{ inputs.repository }}
9494
ref: ${{ inputs.branch }}
@@ -110,14 +110,14 @@ jobs:
110110
CHECKPOINT_DISABLE: "1"
111111
timeout-minutes: 120
112112
steps:
113-
- uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
113+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
114114
with:
115115
repository: ${{ inputs.repository }}
116116
ref: ${{ inputs.branch }}
117117
token: ${{ secrets.GH_PR_TOKEN }}
118118

119119
- name: Setup Node.js
120-
uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4
120+
uses: actions/setup-node@39370e3970a6d050c480ffad4ff0ed4d3fdee5af # v4.1.0
121121
with:
122122
node-version: "20.x"
123123

@@ -150,7 +150,7 @@ jobs:
150150
CHECKPOINT_DISABLE: "1"
151151
timeout-minutes: 360
152152
steps:
153-
- uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
153+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
154154
with:
155155
repository: ${{ inputs.repository }}
156156
ref: ${{ inputs.branch }}
@@ -162,7 +162,7 @@ jobs:
162162
git config --global --add safe.directory $(pwd)
163163
164164
- name: Setup Node.js
165-
uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4
165+
uses: actions/setup-node@39370e3970a6d050c480ffad4ff0ed4d3fdee5af # v4.1.0
166166
with:
167167
node-version: "20.x"
168168

@@ -200,7 +200,7 @@ jobs:
200200
- cdktfDocsConvert
201201
runs-on: ubuntu-latest
202202
steps:
203-
- uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
203+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
204204
with:
205205
repository: ${{ inputs.repository }}
206206
fetch-depth: 0 # complete checkout

.github/workflows/release.yml

+3-3
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ jobs:
2626
env:
2727
CHECKPOINT_DISABLE: "1"
2828
steps:
29-
- uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
29+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
3030
with:
3131
fetch-depth: 0 # gives sentry access to all previous commits
3232
- name: "Add Git safe.directory" # Go 1.18+ started embedding repo info in the build and e.g. building @cdktf/hcl2json fails without this
@@ -155,7 +155,7 @@ jobs:
155155
container:
156156
image: docker.mirror.hashicorp.services/hashicorp/jsii-terraform
157157
steps:
158-
- uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
158+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
159159
- name: installing dependencies
160160
run: |
161161
yarn install --frozen-lockfile
@@ -320,7 +320,7 @@ jobs:
320320
container:
321321
image: docker.mirror.hashicorp.services/hashicorp/jsii-terraform
322322
steps:
323-
- uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
323+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
324324
- name: version
325325
id: get_version
326326
run: |

0 commit comments

Comments
 (0)