Skip to content

Commit a45b1b5

Browse files
pin github deps to shas (#1315)
1 parent 126e41e commit a45b1b5

File tree

5 files changed

+22
-22
lines changed

5 files changed

+22
-22
lines changed

.github/workflows/automerge-dependabot.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ jobs:
1111
steps:
1212
- name: Dependabot metadata
1313
id: metadata
14-
uses: dependabot/[email protected]
14+
uses: dependabot/fetch-metadata@08eff52bf64351f401fb50d4972fa95b9f2c2d1b # v2.4.0
1515
with:
1616
github-token: "${{ secrets.GITHUB_TOKEN }}"
1717
- name: Approve Dependabot PRs

.github/workflows/build-docs.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -12,9 +12,9 @@ jobs:
1212
build-test-deploy:
1313
runs-on: ubuntu-latest
1414
steps:
15-
- uses: actions/checkout@v5
15+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
1616
with: { persist-credentials: false }
17-
- uses: actions/setup-node@v5
17+
- uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
1818
with:
1919
node-version-file: '.nvmrc'
2020

@@ -32,7 +32,7 @@ jobs:
3232

3333
- name: Deploy
3434
if: github.ref == 'refs/heads/main'
35-
uses: JamesIves/github-pages-deploy-action@v4
35+
uses: JamesIves/github-pages-deploy-action@6c2d9db40f9296374acc17b90404b6e8864128c8 # v4.7.3
3636
with:
3737
branch: gh-pages
3838
folder: site

.github/workflows/create-bumb-version-pr.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -17,13 +17,13 @@ jobs:
1717
shell: bash
1818
steps:
1919

20-
- uses: actions/checkout@v5
20+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
2121
with:
2222
fetch-depth: 0
2323
ref: main
2424

2525
- name: Use Node.js from nvmrc
26-
uses: actions/setup-node@v5
26+
uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
2727
with:
2828
node-version-file: '.nvmrc'
2929

@@ -33,7 +33,7 @@ jobs:
3333
./build/bump-version-changelog.js ${{ inputs.version }}
3434
3535
- name: Create Pull Request
36-
uses: peter-evans/create-pull-request@v7
36+
uses: peter-evans/create-pull-request@271a8d0340265f705b14b6d32b9829c1cb33d45e # v7.0.8
3737
with:
3838
commit-message: Bump version to ${{ inputs.version }}
3939
branch: bump-version-to-${{ inputs.version }}

.github/workflows/publish-style-spec.yml

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -13,13 +13,13 @@ jobs:
1313
run:
1414
shell: bash
1515
steps:
16-
- uses: actions/checkout@v5
16+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
1717
with:
1818
fetch-depth: 0
1919
ref: main
2020

2121
- name: Use Node.js from nvmrc
22-
uses: actions/setup-node@v5
22+
uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
2323
with:
2424
node-version-file: '.nvmrc'
2525

@@ -44,26 +44,26 @@ jobs:
4444
if: ${{ needs.release-check.outputs.publish == 'true' }}
4545
runs-on: ubuntu-latest
4646
steps:
47-
- uses: actions/checkout@v5
47+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
4848
with:
4949
fetch-depth: 0
5050
persist-credentials: false
5151

5252
- name: Use Node.js from nvmrc
53-
uses: actions/setup-node@v5
53+
uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
5454
with:
5555
node-version-file: '.nvmrc'
5656
registry-url: 'https://registry.npmjs.org'
5757

5858
- name: Get version
5959
id: package-version
60-
uses: martinbeentjes/[email protected]
60+
uses: martinbeentjes/npm-get-version-action@3cf273023a0dda27efcd3164bdfb51908dd46a5b # v1.3.1
6161

6262
- name: Check tag does not exist yet
6363
run: if git rev-list v${{ steps.package-version.outputs.current-version }}; then echo "Tag already exists. Aborting the release process."; exit 1; fi
6464

6565
- name: Tag commit and push
66-
uses: mathieudutour/[email protected]
66+
uses: mathieudutour/github-tag-action@a22cf08638b34d5badda920f9daf6e72c477b07b # v6.2
6767
with:
6868
github_token: ${{ secrets.GITHUB_TOKEN }}
6969
custom_tag: ${{ steps.package-version.outputs.current-version }}
@@ -96,7 +96,7 @@ jobs:
9696
- name: Create GitHub Release (regular)
9797
id: create_regular_release
9898
if: ${{ steps.prepare_release.outputs.release_type == 'regular' }}
99-
uses: ncipollo/release-action@v1
99+
uses: ncipollo/release-action@b7eabc95ff50cbeeedec83973935c8f306dfcd0b # v1.20.0
100100
env:
101101
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
102102
with:

.github/workflows/test-all.yml

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -13,9 +13,9 @@ jobs:
1313
permissions:
1414
contents: read
1515
steps:
16-
- uses: actions/checkout@v5
16+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
1717
with: { persist-credentials: false }
18-
- uses: actions/setup-node@v5
18+
- uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
1919
with:
2020
node-version-file: '.nvmrc'
2121
- run: npm ci
@@ -29,16 +29,16 @@ jobs:
2929
permissions:
3030
contents: read
3131
steps:
32-
- uses: actions/checkout@v5
32+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
3333
with: { persist-credentials: false }
34-
- uses: actions/setup-node@v5
34+
- uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
3535
with:
3636
node-version-file: '.nvmrc'
3737
- run: npm ci
3838
- run: npm run test-unit-ci
3939
- run: npm run test-integration-ci
4040
- name: Upload coverage reports to Codecov
41-
uses: codecov/codecov-action@v5
41+
uses: codecov/codecov-action@5a1091511ad55cbe89839c7260b706298ca349f7 # v5.5.1
4242
with:
4343
files: ${{ github.workspace }}/coverage/vitest/unit/coverage-final.json, ${{ github.workspace }}/coverage/vitest/integration/coverage-final.json
4444
verbose: true
@@ -53,9 +53,9 @@ jobs:
5353
permissions:
5454
contents: read
5555
steps:
56-
- uses: actions/checkout@v5
56+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
5757
with: { persist-credentials: false }
58-
- uses: actions/setup-node@v5
58+
- uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
5959
with:
6060
node-version-file: '.nvmrc'
6161
- run: npm ci
@@ -64,7 +64,7 @@ jobs:
6464
- run: npm run build
6565
- run: npm run test-build-ci
6666
- name: Upload coverage reports to Codecov
67-
uses: codecov/codecov-action@v5
67+
uses: codecov/codecov-action@5a1091511ad55cbe89839c7260b706298ca349f7 # v5.5.1
6868
with:
6969
files: ${{ github.workspace }}/coverage/vitest/build/coverage-final.json
7070
verbose: true

0 commit comments

Comments
 (0)