diff --git a/ansible-lint-fix/action.yml b/ansible-lint-fix/action.yml index b346bc3..abcd668 100644 --- a/ansible-lint-fix/action.yml +++ b/ansible-lint-fix/action.yml @@ -47,6 +47,6 @@ runs: fi - name: Upload SARIF Report - uses: github/codeql-action/upload-sarif@v3 + uses: github/codeql-action/upload-sarif@9e8d0789d4a0fa9ceb6b1738f7e269594bdd67f0 # v3 with: sarif_file: ansible-lint.sarif diff --git a/biome-check/action.yml b/biome-check/action.yml index 24aad2a..5fafa95 100644 --- a/biome-check/action.yml +++ b/biome-check/action.yml @@ -12,7 +12,7 @@ runs: using: composite steps: - name: Checkout Repository - uses: actions/checkout@v4 + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 - name: Set Git Config uses: ivuorinen/actions/set-git-config@main @@ -31,6 +31,6 @@ runs: biome check . --json > biome-report.json - name: Upload Biome Results - uses: github/codeql-action/upload-sarif@v3 + uses: github/codeql-action/upload-sarif@9e8d0789d4a0fa9ceb6b1738f7e269594bdd67f0 # v3 with: sarif_file: biome-report.json diff --git a/biome-fix/action.yml b/biome-fix/action.yml index 7116e6c..e0de51e 100644 --- a/biome-fix/action.yml +++ b/biome-fix/action.yml @@ -12,7 +12,7 @@ runs: using: composite steps: - name: Checkout Repository - uses: actions/checkout@v4 + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 - name: Set Git Config uses: ivuorinen/actions/set-git-config@main @@ -32,7 +32,7 @@ runs: - name: Push Fixes if: success() - uses: stefanzweifel/git-auto-commit-action@v5 + uses: stefanzweifel/git-auto-commit-action@e348103e9026cc0eee72ae06630dbe30c8bf7a79 # v5 with: commit_message: 'style: autofix Biome violations' add_options: '-u' diff --git a/common-cache/action.yml b/common-cache/action.yml index 9b449ef..2861e8e 100644 --- a/common-cache/action.yml +++ b/common-cache/action.yml @@ -95,7 +95,7 @@ runs: echo "cache-paths=${cache_paths}" >> $GITHUB_OUTPUT - id: cache - uses: actions/cache@v4 + uses: actions/cache@1bd1e32a3bdc45362d1e726936510720a7c30a57 # v4 with: path: ${{ steps.prepare.outputs.cache-paths }} key: ${{ steps.prepare.outputs.cache-key }} diff --git a/compress-images/action.yml b/compress-images/action.yml index 0dcec19..049cf5a 100644 --- a/compress-images/action.yml +++ b/compress-images/action.yml @@ -18,7 +18,7 @@ runs: uses: ivuorinen/actions/set-git-config@main - name: Checkout Repository - uses: actions/checkout@v4 + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 - name: Compress Images id: calibre @@ -29,7 +29,7 @@ runs: - name: Create New Pull Request If Needed if: steps.calibre.outputs.markdown != '' - uses: peter-evans/create-pull-request@v7 + uses: peter-evans/create-pull-request@67ccf781d68cd99b580ae25a5c18a1cc84ffff1f # v7 with: title: Compressed Images Nightly branch-suffix: timestamp diff --git a/csharp-build/action.yml b/csharp-build/action.yml index 517b72d..a7e8d5f 100644 --- a/csharp-build/action.yml +++ b/csharp-build/action.yml @@ -22,7 +22,7 @@ runs: default-version: '7.0' - name: Setup .NET SDK - uses: actions/setup-dotnet@v4 + uses: actions/setup-dotnet@3951f0dfe7a07e2313ec93c75700083e2005cbab # v4 with: dotnet-version: '${{ steps.detect-dotnet-version.outputs.dotnet-version }}' @@ -40,7 +40,7 @@ runs: dotnet test --configuration Release --no-build --collect:"XPlat Code Coverage" --logger "trx;LogFileName=test-results.trx" - name: Upload Test Results - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4 with: name: test-results path: | diff --git a/csharp-lint-check/action.yml b/csharp-lint-check/action.yml index f41837a..b9fee06 100644 --- a/csharp-lint-check/action.yml +++ b/csharp-lint-check/action.yml @@ -22,7 +22,7 @@ runs: default-version: '7.0' - name: Setup .NET SDK - uses: actions/setup-dotnet@v4 + uses: actions/setup-dotnet@3951f0dfe7a07e2313ec93c75700083e2005cbab # v4 with: dotnet-version: '${{ steps.detect-dotnet-version.outputs.dotnet-version }}' @@ -40,6 +40,6 @@ runs: fi - name: Upload SARIF Report - uses: github/codeql-action/upload-sarif@v3 + uses: github/codeql-action/upload-sarif@9e8d0789d4a0fa9ceb6b1738f7e269594bdd67f0 # v3 with: sarif_file: dotnet-format.sarif diff --git a/csharp-publish/action.yml b/csharp-publish/action.yml index e322131..573922e 100644 --- a/csharp-publish/action.yml +++ b/csharp-publish/action.yml @@ -26,7 +26,7 @@ runs: default-version: '7.0' - name: Setup .NET SDK - uses: actions/setup-dotnet@v4 + uses: actions/setup-dotnet@3951f0dfe7a07e2313ec93c75700083e2005cbab # v4 with: dotnet-version: '${{ steps.detect-dotnet-version.outputs.dotnet-version }}' diff --git a/docker-build/action.yml b/docker-build/action.yml index 3aa6e2c..b1d2f27 100644 --- a/docker-build/action.yml +++ b/docker-build/action.yml @@ -92,13 +92,13 @@ runs: fi - name: Set up QEMU - uses: docker/setup-qemu-action@v3 + uses: docker/setup-qemu-action@4574d27a4764455b42196d70a065bc6853246a25 # v3 with: platforms: ${{ inputs.architectures }} - name: Set up Docker Buildx id: buildx - uses: docker/setup-buildx-action@v3 + uses: docker/setup-buildx-action@f7ce87c1d6bead3e36075b2ce75da1f6cc28aaca # v3 with: version: latest platforms: ${{ inputs.architectures }} diff --git a/docker-publish-gh/action.yml b/docker-publish-gh/action.yml index f20e4ab..760e6af 100644 --- a/docker-publish-gh/action.yml +++ b/docker-publish-gh/action.yml @@ -97,12 +97,12 @@ runs: done - name: Set up QEMU - uses: docker/setup-qemu-action@v3 + uses: docker/setup-qemu-action@4574d27a4764455b42196d70a065bc6853246a25 # v3 with: platforms: ${{ inputs.platforms }} - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v3 + uses: docker/setup-buildx-action@f7ce87c1d6bead3e36075b2ce75da1f6cc28aaca # v3 with: platforms: ${{ inputs.platforms }} @@ -133,7 +133,7 @@ runs: echo "tags=${processed_tags}" >> $GITHUB_OUTPUT - name: Log in to GitHub Container Registry - uses: docker/login-action@v3 + uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3 with: registry: ${{ inputs.registry }} username: ${{ github.actor }} @@ -141,7 +141,7 @@ runs: - name: Set up Cosign if: inputs.provenance == 'true' - uses: sigstore/cosign-installer@v3 + uses: sigstore/cosign-installer@c56c2d3e59e4281cc41dea2217323ba5694b171e # v3 - name: Publish Image id: publish diff --git a/docker-publish-hub/action.yml b/docker-publish-hub/action.yml index e27bbdd..6c52d74 100644 --- a/docker-publish-hub/action.yml +++ b/docker-publish-hub/action.yml @@ -105,12 +105,12 @@ runs: fi - name: Set up QEMU - uses: docker/setup-qemu-action@v3 + uses: docker/setup-qemu-action@4574d27a4764455b42196d70a065bc6853246a25 # v3 with: platforms: ${{ inputs.platforms }} - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v3 + uses: docker/setup-buildx-action@f7ce87c1d6bead3e36075b2ce75da1f6cc28aaca # v3 with: platforms: ${{ inputs.platforms }} @@ -144,14 +144,14 @@ runs: echo "repo-url=https://hub.docker.com/r/${full_name}" >> $GITHUB_OUTPUT - name: Log in to Docker Hub - uses: docker/login-action@v3 + uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3 with: username: ${{ inputs.username }} password: ${{ inputs.password }} - name: Set up Cosign if: inputs.provenance == 'true' - uses: sigstore/cosign-installer@v3 + uses: sigstore/cosign-installer@c56c2d3e59e4281cc41dea2217323ba5694b171e # v3 - name: Update Docker Hub Description if: inputs.repository-description != '' || inputs.readme-file != '' diff --git a/eslint-check/action.yml b/eslint-check/action.yml index 57d797d..21be44e 100644 --- a/eslint-check/action.yml +++ b/eslint-check/action.yml @@ -239,7 +239,7 @@ runs: - name: Upload ESLint Results if: always() && inputs.report-format == 'sarif' - uses: github/codeql-action/upload-sarif@v3 + uses: github/codeql-action/upload-sarif@9e8d0789d4a0fa9ceb6b1738f7e269594bdd67f0 # v3 with: sarif_file: ${{ inputs.working-directory }}/reports/eslint.sarif category: eslint diff --git a/eslint-fix/action.yml b/eslint-fix/action.yml index adc9c9e..d252c44 100644 --- a/eslint-fix/action.yml +++ b/eslint-fix/action.yml @@ -12,7 +12,7 @@ runs: using: composite steps: - name: Checkout Repository - uses: actions/checkout@v4 + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 - name: Set Git Config uses: ivuorinen/actions/set-git-config@main @@ -32,7 +32,7 @@ runs: - name: Push Fixes if: always() - uses: stefanzweifel/git-auto-commit-action@v5 + uses: stefanzweifel/git-auto-commit-action@e348103e9026cc0eee72ae06630dbe30c8bf7a79 # v5 with: commit_message: 'style: autofix ESLint violations' add_options: '-u' diff --git a/go-build/action.yml b/go-build/action.yml index 67c4ef3..1717102 100644 --- a/go-build/action.yml +++ b/go-build/action.yml @@ -24,7 +24,7 @@ runs: uses: ivuorinen/actions/go-version-detect@main - name: Setup Go - uses: actions/setup-go@v5 + uses: actions/setup-go@f111f3307d8850f501ac008e886eec1fd1932a34 # v5 with: go-version: '${{ steps.detect-go-version.outputs.go-version }}' diff --git a/go-lint/action.yml b/go-lint/action.yml index dd0907d..8132338 100644 --- a/go-lint/action.yml +++ b/go-lint/action.yml @@ -106,7 +106,7 @@ runs: done - name: Setup Go - uses: actions/setup-go@v5 + uses: actions/setup-go@f111f3307d8850f501ac008e886eec1fd1932a34 # v5 with: go-version: ${{ inputs.go-version }} cache: true @@ -114,7 +114,7 @@ runs: - name: Set up Cache id: cache if: inputs.cache == 'true' - uses: actions/cache@v4 + uses: actions/cache@1bd1e32a3bdc45362d1e726936510720a7c30a57 # v4 with: path: | ~/.cache/golangci-lint @@ -266,7 +266,7 @@ runs: - name: Upload Lint Results if: always() && inputs.report-format == 'sarif' - uses: github/codeql-action/upload-sarif@v3 + uses: github/codeql-action/upload-sarif@9e8d0789d4a0fa9ceb6b1738f7e269594bdd67f0 # v3 with: sarif_file: ${{ inputs.working-directory }}/reports/golangci-lint.sarif category: golangci-lint diff --git a/node-setup/action.yml b/node-setup/action.yml index 77f0e9d..9f3f3aa 100644 --- a/node-setup/action.yml +++ b/node-setup/action.yml @@ -161,7 +161,7 @@ runs: - name: Setup Node.js id: setup - uses: actions/setup-node@v4 + uses: actions/setup-node@1d0ff469b7ec7b3cb9d8673fde0c81c44821de2a # v4 with: node-version: ${{ steps.version.outputs.version }} registry-url: ${{ inputs.registry-url }} @@ -216,7 +216,7 @@ runs: - name: Setup Caching if: inputs.cache == 'true' id: deps-cache - uses: actions/cache@v4 + uses: actions/cache@1bd1e32a3bdc45362d1e726936510720a7c30a57 # v4 with: path: | **/node_modules diff --git a/php-composer/action.yml b/php-composer/action.yml index 2eee1ff..bc8ea23 100644 --- a/php-composer/action.yml +++ b/php-composer/action.yml @@ -89,7 +89,7 @@ runs: - name: Setup PHP id: php - uses: shivammathur/setup-php@v2 + uses: shivammathur/setup-php@9e72090525849c5e82e596468b86eb55e9cc5401 # v2 with: php-version: ${{ inputs.php }} extensions: ${{ inputs.extensions }} @@ -172,7 +172,7 @@ runs: - name: Cache Composer packages id: composer-cache - uses: actions/cache@v4 + uses: actions/cache@1bd1e32a3bdc45362d1e726936510720a7c30a57 # v4 with: path: | vendor diff --git a/php-laravel-phpunit/action.yml b/php-laravel-phpunit/action.yml index 7742dd7..b711ba7 100644 --- a/php-laravel-phpunit/action.yml +++ b/php-laravel-phpunit/action.yml @@ -43,18 +43,18 @@ outputs: runs: using: composite steps: - - uses: shivammathur/setup-php@v2 + - uses: shivammathur/setup-php@9e72090525849c5e82e596468b86eb55e9cc5401 # v2 with: php-version: ${{ inputs.php-version }} php-version-file: ${{ inputs.php-version-file }} extensions: ${{ inputs.extensions }} coverage: ${{ inputs.coverage }} - - uses: actions/checkout@v4 + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 - name: 'Check file existence' id: check_files - uses: andstor/file-existence-action@v3 + uses: andstor/file-existence-action@076e0072799f4942c8bc574a82233e1e4d13e9d6 # v3 with: files: 'package.json, artisan' diff --git a/pr-lint/action.yml b/pr-lint/action.yml index a737cc5..31c397f 100644 --- a/pr-lint/action.yml +++ b/pr-lint/action.yml @@ -14,7 +14,7 @@ runs: steps: # Git Checkout - name: Checkout Code - uses: actions/checkout@v4 + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 with: token: ${{ github.token }} @@ -30,7 +30,7 @@ runs: - name: MegaLinter # You can override MegaLinter flavor used to have faster performances # More info at https://megalinter.io/latest/flavors/ - uses: oxsecurity/megalinter@v8 + uses: oxsecurity/megalinter@ec124f7998718d79379a3c5b39f5359952baf21d # v8 id: ml # All available variables are described in documentation @@ -79,7 +79,7 @@ runs: # Upload MegaLinter artifacts - name: Archive production artifacts if: success() || failure() - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4 with: name: MegaLinter reports include-hidden-files: 'true' @@ -120,7 +120,7 @@ runs: # Create pull request if applicable # (for now works only on PR from same repository, not from forks) - name: Create Pull Request with applied fixes - uses: peter-evans/create-pull-request@v7 + uses: peter-evans/create-pull-request@67ccf781d68cd99b580ae25a5c18a1cc84ffff1f # v7 id: cpr if: env.APPLY_FIXES_IF_PR == 'true' with: @@ -144,7 +144,7 @@ runs: run: sudo chown -Rc $UID .git/ - name: Commit and push applied linter fixes - uses: stefanzweifel/git-auto-commit-action@v5 + uses: stefanzweifel/git-auto-commit-action@e348103e9026cc0eee72ae06630dbe30c8bf7a79 # v5 if: env.APPLY_FIXES_IF_COMMIT == 'true' with: branch: >- diff --git a/pre-commit/action.yml b/pre-commit/action.yml index 1f54f25..17dce2d 100644 --- a/pre-commit/action.yml +++ b/pre-commit/action.yml @@ -50,13 +50,13 @@ runs: shell: bash - name: Run pre-commit - uses: pre-commit/action@v3.0.1 + uses: pre-commit/action@2c7b3805fd2a0fd8c1884dcaebf91fc102a13ecd # v3.0.1 with: extra_args: --config ${{ inputs.pre-commit-config }} ${{ steps.set-option.outputs.option }} - name: Push pre-commit fixes if: always() # Push changes even when pre-commit fails - uses: stefanzweifel/git-auto-commit-action@v5 + uses: stefanzweifel/git-auto-commit-action@e348103e9026cc0eee72ae06630dbe30c8bf7a79 # v5 with: commit_message: 'style(pre-commit): autofix' add_options: -u diff --git a/prettier-check/action.yml b/prettier-check/action.yml index 7b4cee2..e350504 100644 --- a/prettier-check/action.yml +++ b/prettier-check/action.yml @@ -102,7 +102,7 @@ runs: - name: Set up Cache id: cache - uses: actions/cache@v4 + uses: actions/cache@1bd1e32a3bdc45362d1e726936510720a7c30a57 # v4 if: inputs.cache == 'true' with: path: | @@ -305,7 +305,7 @@ runs: - name: Upload Prettier Results if: always() && inputs.report-format == 'sarif' - uses: github/codeql-action/upload-sarif@v3 + uses: github/codeql-action/upload-sarif@9e8d0789d4a0fa9ceb6b1738f7e269594bdd67f0 # v3 with: sarif_file: ${{ inputs.working-directory }}/reports/prettier.sarif category: prettier diff --git a/prettier-fix/action.yml b/prettier-fix/action.yml index 9d7f1d5..14ce02b 100644 --- a/prettier-fix/action.yml +++ b/prettier-fix/action.yml @@ -12,7 +12,7 @@ runs: using: 'composite' steps: - name: Checkout Repository - uses: actions/checkout@v4 + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 - name: Set Git Config uses: ivuorinen/actions/set-git-config@main @@ -32,7 +32,7 @@ runs: - name: Push Fixes if: always() - uses: stefanzweifel/git-auto-commit-action@v5 + uses: stefanzweifel/git-auto-commit-action@e348103e9026cc0eee72ae06630dbe30c8bf7a79 # v5 with: commit_message: 'style: autofix Prettier violations' add_options: '-u' diff --git a/python-lint-fix/action.yml b/python-lint-fix/action.yml index 9338ca5..780a10f 100644 --- a/python-lint-fix/action.yml +++ b/python-lint-fix/action.yml @@ -49,7 +49,7 @@ runs: using: composite steps: - name: Setup Python - uses: actions/setup-python@v5 + uses: actions/setup-python@42375524e23c412d93fb67b49958b491fce71c38 # v5 with: python-version: ${{ inputs.python-version }} cache: 'pip' @@ -213,7 +213,7 @@ runs: - name: Upload SARIF Report if: steps.check-files.outputs.result == 'found' - uses: github/codeql-action/upload-sarif@v3 + uses: github/codeql-action/upload-sarif@9e8d0789d4a0fa9ceb6b1738f7e269594bdd67f0 # v3 with: sarif_file: ${{ inputs.working-directory }}/reports/flake8.sarif category: 'python-lint' diff --git a/release-monthly/action.yml b/release-monthly/action.yml index e0c609b..81db193 100644 --- a/release-monthly/action.yml +++ b/release-monthly/action.yml @@ -62,7 +62,7 @@ runs: fi - name: Checkout Repository - uses: actions/checkout@v4 + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 with: fetch-depth: 0 # Fetch all history for tag comparison diff --git a/stale/action.yml b/stale/action.yml index 6b36443..a610232 100644 --- a/stale/action.yml +++ b/stale/action.yml @@ -11,7 +11,7 @@ runs: using: composite steps: - name: 🚀 Run stale - uses: actions/stale@v9.1.0 + uses: actions/stale@5bef64f19d7facfb25b37b414482c7164d639639 # v9.1.0 with: repo-token: ${{ github.token }} days-before-stale: 30 diff --git a/sync-labels/action.yml b/sync-labels/action.yml index 79b0064..b11f928 100644 --- a/sync-labels/action.yml +++ b/sync-labels/action.yml @@ -26,7 +26,7 @@ runs: > ${{ inputs.labels }} - name: 🚀 Run Label Syncer - uses: micnncim/action-label-syncer@v1.3.0 + uses: micnncim/action-label-syncer@3abd5ab72fda571e69fffd97bd4e0033dd5f495c # v1.3.0 env: GITHUB_TOKEN: ${{ github.token }} with: diff --git a/terraform-lint-fix/action.yml b/terraform-lint-fix/action.yml index 0bd5850..0c32f10 100644 --- a/terraform-lint-fix/action.yml +++ b/terraform-lint-fix/action.yml @@ -82,7 +82,7 @@ runs: - name: Setup Terraform if: steps.check-files.outputs.found == 'true' - uses: hashicorp/setup-terraform@v3 + uses: hashicorp/setup-terraform@b9cd54a3c349d3f38e8881555d616ced269862dd # v3 with: terraform_version: ${{ inputs.terraform-version }} terraform_wrapper: false @@ -225,7 +225,7 @@ runs: - name: Upload SARIF Report if: steps.check-files.outputs.found == 'true' && inputs.format == 'sarif' - uses: github/codeql-action/upload-sarif@v3 + uses: github/codeql-action/upload-sarif@9e8d0789d4a0fa9ceb6b1738f7e269594bdd67f0 # v3 with: sarif_file: ${{ inputs.working-directory }}/reports/tflint.sarif category: terraform-lint