diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 000000000..2c48305b7 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,11 @@ +version: 2 +updates: + - package-ecosystem: "github-actions" + directory: "/" + groups: + github-actions: + patterns: ["*"] + schedule: + interval: "weekly" + cooldown: + default-days: 7 diff --git a/.github/workflows/azure-dev-validate.yml b/.github/workflows/azure-dev-validate.yml index 7d5cef141..4844db6ef 100644 --- a/.github/workflows/azure-dev-validate.yml +++ b/.github/workflows/azure-dev-validate.yml @@ -16,10 +16,10 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v3 + uses: actions/checkout@a37ce9120846195fa4ece8f58b268e6043cb2f26 # v3.7.0 - name: Build Bicep for linting - uses: azure/CLI@v1 + uses: azure/CLI@4db43908b9df2e7ac93c8275a8f9a448c59338dd # v1.0.9 with: inlineScript: az config set bicep.use_binary_from_path=false && az bicep build -f infra/main.bicep --stdout @@ -33,6 +33,6 @@ jobs: GDN_TEMPLATEANALYZER_VERBOSE: 1 - name: Upload alerts to Security tab - uses: github/codeql-action/upload-sarif@v2 + uses: github/codeql-action/upload-sarif@b8d3b6e8af63cde30bdc382c0bc28114f4346c88 # v2.28.1 with: sarif_file: ${{ steps.msdo.outputs.sarifFile }} diff --git a/.github/workflows/open-ai-app.yml b/.github/workflows/open-ai-app.yml index b7dd667d6..9881d6882 100644 --- a/.github/workflows/open-ai-app.yml +++ b/.github/workflows/open-ai-app.yml @@ -15,10 +15,10 @@ jobs: steps: - name: 🌱 Checkout to the branch - uses: actions/checkout@v4 + uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 - name: 🍏 Set up Node.js version - uses: actions/setup-node@v4 + uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 with: node-version: "20.x" @@ -50,7 +50,7 @@ jobs: ls ./site-deploy - name: ⬆️ Publish Next Application artifact - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 with: name: Nextjs-site path: ./site-deploy/Nextjs-site.zip @@ -63,23 +63,23 @@ jobs: steps: - name: 🍏 Set up Node.js version - uses: actions/setup-node@v4 + uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 with: node-version: "20.x" - name: ⬇️ Download artifact from build job - uses: actions/download-artifact@v4.1.8 + uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4.1.8 with: name: Nextjs-site - name: 🗝️ Azure Login - uses: azure/login@v2.2.0 + uses: azure/login@a65d910e8af852a8061c627c456678983e180302 # v2.2.0 with: creds: ${{ secrets.AZURE_CREDENTIALS }} # Set the build during deployment setting to false. This setting was added in the templates to all azd to work, but breaks deployment via webapps-deploy - name: Azure CLI script - uses: azure/CLI@v2.1.0 + uses: azure/CLI@089eac9d8cc39f5d003e94f8b65efc51076c9cbd # v2.1.0 with: inlineScript: | rg=$(az webapp list --query "[?name=='${{ secrets.AZURE_APP_SERVICE_NAME }}'].resourceGroup" --output tsv) @@ -91,7 +91,7 @@ jobs: - name: 🚀 Deploy to Azure Web App id: deploy-to-webapp - uses: azure/webapps-deploy@v3.0.1 + uses: azure/webapps-deploy@de617f46172a906d0617bb0e50d81e9e3aec24c8 # v3.0.1 with: app-name: ${{ secrets.AZURE_APP_SERVICE_NAME }} package: ${{ github.workspace }}/Nextjs-site.zip