Skip to content

Commit 9ceffb4

Browse files
chore(deps): pin dependencies (#66)
* chore(deps): pin dependencies Signed-off-by: Magnus Ullberg <magnus@ullberg.us>
1 parent ab59c02 commit 9ceffb4

15 files changed

Lines changed: 55 additions & 54 deletions

.github/workflows/codacy.yml

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -23,11 +23,11 @@ jobs:
2323
steps:
2424
# Checkout the repository to the GitHub Actions runner
2525
- name: Checkout code
26-
uses: actions/checkout@v4
26+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
2727

2828
# Execute Codacy Analysis CLI and generate a SARIF output with the security issues identified during the analysis
2929
- name: Run Codacy Analysis CLI
30-
uses: codacy/codacy-analysis-cli-action@d840f886c4bd4edc059706d09c6a1586111c540b
30+
uses: codacy/codacy-analysis-cli-action@30783d03e758713bb5ed7b79292cfb14b9dd9a4a
3131
with:
3232
# Check https://github.com/codacy/codacy-analysis-cli#project-token to get your project token from your Codacy repository
3333
# You can also omit the token and run the tools that support default configurations
@@ -43,6 +43,7 @@ jobs:
4343

4444
# Upload the SARIF file generated in the previous step
4545
- name: Upload SARIF results file
46-
uses: github/codeql-action/upload-sarif@v3
46+
uses: github/codeql-action/upload-sarif@d3ced5c96c16c4332e2a61eb6f3649d6f1b20bb8 # v3
4747
with:
4848
sarif_file: results.sarif
49+
category: codacy

.github/workflows/lint.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -12,12 +12,12 @@ jobs:
1212
runs-on: ubuntu-latest
1313
steps:
1414
- name: Clone the code
15-
uses: actions/checkout@v6
15+
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6
1616

1717
- name: Setup Go
18-
uses: actions/setup-go@v6
18+
uses: actions/setup-go@4dc6199c7b1a012772edbd06daecab0f50c9053c # v6
1919
with:
2020
go-version-file: go.mod
2121

2222
- name: Run linter
23-
uses: golangci/golangci-lint-action@v9
23+
uses: golangci/golangci-lint-action@e7fa5ac41e1cf5b7d48e45e42232ce7ada589601 # v9

.github/workflows/pr-check.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -25,10 +25,10 @@ jobs:
2525
rm -rf /tmp/golangci-lint-${GOLANGCI_LINT_VERSION}-linux-amd64* golangci-lint-${GOLANGCI_LINT_VERSION}-linux-amd64.tar.gz
2626
2727
- name: Clone the code
28-
uses: actions/checkout@v6
28+
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6
2929

3030
- name: Setup Go
31-
uses: actions/setup-go@v6
31+
uses: actions/setup-go@4dc6199c7b1a012772edbd06daecab0f50c9053c # v6
3232
with:
3333
go-version-file: go.mod
3434

.github/workflows/pr-fuzz.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -17,10 +17,10 @@ jobs:
1717
runs-on: ubuntu-latest
1818
steps:
1919
- name: Checkout
20-
uses: actions/checkout@v6
20+
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6
2121

2222
- name: Setup Go
23-
uses: actions/setup-go@v6
23+
uses: actions/setup-go@4dc6199c7b1a012772edbd06daecab0f50c9053c # v6
2424
with:
2525
go-version-file: go.mod
2626

@@ -34,7 +34,7 @@ jobs:
3434

3535
- name: Upload fuzz logs
3636
if: always()
37-
uses: actions/upload-artifact@v5
37+
uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5
3838
with:
3939
name: pr-fuzz-logs
4040
path: tmp/fuzz.log

.github/workflows/pr-labeler.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,10 +17,10 @@ jobs:
1717

1818
steps:
1919
- name: ⤵️ Check out code from GitHub
20-
uses: actions/checkout@v6
20+
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6
2121

2222
- name: 🏷️ Apply labels
23-
uses: actions/labeler@v6
23+
uses: actions/labeler@634933edcd8ababfe52f92936142cc22ac488b1b # v6
2424
with:
2525
configuration-path: .github/labeler.yml
2626
repo-token: "${{ secrets.GITHUB_TOKEN }}"

.github/workflows/pr-size-labeler.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ jobs:
1414

1515
steps:
1616
- name: size-label
17-
uses: "pascalgn/size-label-action@v0.5.5"
17+
uses: "pascalgn/size-label-action@f8edde36b3be04b4f65dcfead05dc8691b374348" # v0.5.5
1818
env:
1919
GITHUB_TOKEN: "${{ secrets.GITHUB_TOKEN }}"
2020
with:

.github/workflows/pr-verify-labels.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ jobs:
1717

1818
steps:
1919
- name: 🏷 Verify PR has a valid label
20-
uses: jesusvasquez333/verify-pr-label-action@v1.4.0
20+
uses: jesusvasquez333/verify-pr-label-action@657d111bbbe13e22bbd55870f1813c699bde1401 # v1.4.0
2121
with:
2222
github-token: "${{ secrets.GITHUB_TOKEN }}"
2323
invalid-labels: >-

.github/workflows/release.yml

Lines changed: 20 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -54,24 +54,24 @@ jobs:
5454
packages: write
5555
steps:
5656
- name: Checkout
57-
uses: actions/checkout@v6
57+
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6
5858

5959
- name: Set up Go
60-
uses: actions/setup-go@v6
60+
uses: actions/setup-go@4dc6199c7b1a012772edbd06daecab0f50c9053c # v6
6161
with:
6262
go-version-file: 'go.mod'
6363

6464
- name: Run Tests
6565
run: make test
6666

6767
- name: Set up QEMU
68-
uses: docker/setup-qemu-action@v3
68+
uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130 # v3
6969

7070
- name: Set up Docker Buildx
71-
uses: docker/setup-buildx-action@v3
71+
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3
7272

7373
- name: Login to GitHub Container Registry
74-
uses: docker/login-action@v3
74+
uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3
7575
with:
7676
registry: ${{ env.REGISTRY }}
7777
username: ${{ github.actor }}
@@ -98,10 +98,10 @@ jobs:
9898
packages: write
9999
steps:
100100
- name: Checkout
101-
uses: actions/checkout@v6
101+
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6
102102

103103
- name: Set up Node.js
104-
uses: actions/setup-node@v6
104+
uses: actions/setup-node@2028fbc5c25fe9cf00d9f06a71cc4710d4507903 # v6
105105
with:
106106
node-version: '24'
107107

@@ -114,13 +114,13 @@ jobs:
114114
run: yarn build
115115

116116
- name: Set up QEMU
117-
uses: docker/setup-qemu-action@v3
117+
uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130 # v3
118118

119119
- name: Set up Docker Buildx
120-
uses: docker/setup-buildx-action@v3
120+
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3
121121

122122
- name: Login to GitHub Container Registry
123-
uses: docker/login-action@v3
123+
uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3
124124
with:
125125
registry: ${{ env.REGISTRY }}
126126
username: ${{ github.actor }}
@@ -147,16 +147,16 @@ jobs:
147147
packages: write
148148
steps:
149149
- name: Checkout
150-
uses: actions/checkout@v6
150+
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6
151151

152152
- name: Set up QEMU
153-
uses: docker/setup-qemu-action@v3
153+
uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130 # v3
154154

155155
- name: Set up Docker Buildx
156-
uses: docker/setup-buildx-action@v3
156+
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3
157157

158158
- name: Login to GitHub Container Registry
159-
uses: docker/login-action@v3
159+
uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3
160160
with:
161161
registry: ${{ env.REGISTRY }}
162162
username: ${{ github.actor }}
@@ -185,10 +185,10 @@ jobs:
185185
packages: write
186186
steps:
187187
- name: Checkout
188-
uses: actions/checkout@v6
188+
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6
189189

190190
- name: Login to GitHub Container Registry
191-
uses: docker/login-action@v3
191+
uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3
192192
with:
193193
registry: ${{ env.REGISTRY }}
194194
username: ${{ github.actor }}
@@ -217,10 +217,10 @@ jobs:
217217
packages: write
218218
steps:
219219
- name: Checkout
220-
uses: actions/checkout@v6
220+
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6
221221

222222
- name: Login to GitHub Container Registry
223-
uses: docker/login-action@v3
223+
uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3
224224
with:
225225
registry: ${{ env.REGISTRY }}
226226
username: ${{ github.actor }}
@@ -248,7 +248,7 @@ jobs:
248248
packages: write
249249
steps:
250250
- name: Checkout
251-
uses: actions/checkout@v6
251+
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6
252252
with:
253253
fetch-depth: 0
254254

@@ -296,7 +296,7 @@ jobs:
296296
cat release_notes.md
297297
298298
- name: Create Release
299-
uses: softprops/action-gh-release@v2
299+
uses: softprops/action-gh-release@5be0e66d93ac7ed76da52eca8bb058f665c3a5fe # v2
300300
with:
301301
tag_name: ${{ needs.prepare.outputs.version_tag }}
302302
name: Release ${{ needs.prepare.outputs.version_tag }}

.github/workflows/schedule-codeowners.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,10 +14,10 @@ jobs:
1414
runs-on: ubuntu-latest
1515
steps:
1616
- name: ⤵️ Check out code from GitHub
17-
uses: actions/checkout@v6
17+
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6
1818

1919
- name: ✅ GitHub CODEOWNERS Validator
20-
uses: mszostok/codeowners-validator@v0.7.4
20+
uses: mszostok/codeowners-validator@7f3f5e28c6d7b8dfae5731e54ce2272ca384592f # v0.7.4
2121
with:
2222
github_access_token: "${{ secrets.GITHUB_TOKEN }}"
2323
checks: "files,duppatterns,syntax"

.github/workflows/schedule-fuzz.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -19,10 +19,10 @@ jobs:
1919
runs-on: ubuntu-latest
2020
steps:
2121
- name: Checkout
22-
uses: actions/checkout@v6
22+
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6
2323

2424
- name: Setup Go
25-
uses: actions/setup-go@v6
25+
uses: actions/setup-go@4dc6199c7b1a012772edbd06daecab0f50c9053c # v6
2626
with:
2727
go-version-file: go.mod
2828

@@ -36,7 +36,7 @@ jobs:
3636

3737
- name: Upload weekly fuzz logs
3838
if: always()
39-
uses: actions/upload-artifact@v5
39+
uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5
4040
with:
4141
name: schedule-fuzz-logs
4242
path: tmp/fuzz.log
@@ -49,7 +49,7 @@ jobs:
4949

5050
- name: Create issue on failure
5151
if: ${{ failure() }}
52-
uses: actions/github-script@v8
52+
uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8
5353
with:
5454
script: |
5555
const fs = require('fs');

0 commit comments

Comments
 (0)