Skip to content

Commit 3db646a

Browse files
Copilotbaynezy
andauthored
Use full commit SHA hashes for GitHub Actions (#236)
* Initial plan * Use full commit SHA hashes for all external GitHub Actions Co-authored-by: baynezy <1049999+baynezy@users.noreply.github.com> --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: baynezy <1049999+baynezy@users.noreply.github.com> Co-authored-by: Simon Baynes <baynezy@gmail.com>
1 parent 32d4384 commit 3db646a

13 files changed

+26
-25
lines changed

.github/workflows/blocked-issue.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ jobs:
1818
runs-on: ubuntu-latest
1919
steps:
2020
- name: Checkout repo
21-
uses: actions/checkout@v4
21+
uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955
2222
- name: Add blocked label if issue is blocked
2323
run: |
2424
body=$BODY

.github/workflows/branch-hotfix.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -28,23 +28,23 @@ jobs:
2828
needs: [get-version]
2929
runs-on: ubuntu-latest
3030
steps:
31-
- uses: actions/checkout@v5
31+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
3232
with:
3333
ref: ${{ github.head_ref }}
3434
- name: Increment Version
3535
id: increment_version
3636
run: |
3737
echo "patch_version=$(($(cat semver.json | jq -r '.patch')+1))" > $GITHUB_OUTPUT
3838
- name: Store New Version
39-
uses: Afterlife-Guide/SemVer.Action@1.1.1.16
39+
uses: Afterlife-Guide/SemVer.Action@23e59d321ba2dbb6736fd78076f9b279fecbeaf2
4040
with:
4141
path: semver.json
4242
major-version: ${{ needs.get-version.outputs.major }}
4343
minor-version: ${{ needs.get-version.outputs.minor }}
4444
patch-version: ${{ steps.increment_version.outputs.patch_version }}
4545
build-version: ${{ github.run_number }}
4646
- name: Update changelog
47-
uses: baynezy/ChangeLogger.Action@1.1.1.13
47+
uses: baynezy/ChangeLogger.Action@1e22c0074e1cec3c97ca3416db7ab79924310492
4848
with:
4949
tag: ${{ needs.get-version.outputs.major }}.${{ needs.get-version.outputs.minor }}.${{ steps.increment_version.outputs.patch_version }}.${{ github.run_number }}
5050

.github/workflows/branch-master.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,7 @@ jobs:
4141
needs: [push-package]
4242
runs-on: ubuntu-latest
4343
steps:
44-
- uses: actions/checkout@v5
44+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
4545
- name: Create Pull Request
4646
env:
4747
GH_TOKEN: ${{ secrets.CREATE_PR_TOKEN }}

.github/workflows/completed-feature-workflow.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ jobs:
1414
runs-on: ubuntu-latest
1515
steps:
1616
- name: Checkout repo
17-
uses: actions/checkout@v5
17+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
1818
- name: Extract Issue Number
1919
shell: bash
2020
env:

.github/workflows/draft-new-release.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -22,12 +22,12 @@ jobs:
2222
name: "Draft a new release"
2323
runs-on: ubuntu-latest
2424
steps:
25-
- uses: actions/checkout@v5
25+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
2626
- name: Create release branch
2727
run: git checkout -b release/${{ github.event.inputs.major_version }}.${{ github.event.inputs.minor_version }}.${{ github.event.inputs.patch_version }}.${{ github.run_number }}
2828

2929
- name: Update Version Number
30-
uses: Afterlife-Guide/SemVer.Action@1.1.1.16
30+
uses: Afterlife-Guide/SemVer.Action@23e59d321ba2dbb6736fd78076f9b279fecbeaf2
3131
with:
3232
path: semver.json
3333
major-version: ${{ github.event.inputs.major_version }}
@@ -36,7 +36,7 @@ jobs:
3636
build-version: ${{ github.run_number }}
3737

3838
- name: Update changelog
39-
uses: baynezy/ChangeLogger.Action@1.1.1.13
39+
uses: baynezy/ChangeLogger.Action@1e22c0074e1cec3c97ca3416db7ab79924310492
4040
with:
4141
tag: ${{ github.event.inputs.major_version }}.${{ github.event.inputs.minor_version }}.${{ github.event.inputs.patch_version }}.${{ github.run_number }}
4242

.github/workflows/gitstream.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,7 @@ jobs:
3838
name: gitStream workflow automation
3939
steps:
4040
- name: Evaluate Rules
41-
uses: linear-b/gitstream-github-action@v1
41+
uses: linear-b/gitstream-github-action@33597e470d599adf6fbc00360897d2aa46e4064b
4242
id: rules-engine
4343
with:
4444
full_repository: ${{ github.event.inputs.full_repository }}

.github/workflows/in-progress-feature-workflow.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ jobs:
1313
runs-on: ubuntu-latest
1414
steps:
1515
- name: Checkout repo
16-
uses: actions/checkout@v5
16+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
1717
- name: Extract Issue Number
1818
shell: bash
1919
run: echo "issue=$(echo ${GITHUB_REF#refs/heads/} | sed 's|[^0-9]||g')" >> $GITHUB_OUTPUT

.github/workflows/label-configurer.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,9 +14,9 @@ jobs:
1414
runs-on: ubuntu-latest
1515
steps:
1616
- name: Checkout
17-
uses: actions/checkout@v5
17+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
1818
- name: Run Labeler
19-
uses: crazy-max/ghaction-github-labeler@v5
19+
uses: crazy-max/ghaction-github-labeler@24d110aa46a59976b8a7f35518cb7f14f434c916
2020
with:
2121
github-token: ${{ secrets.GITHUB_TOKEN }}
2222
exclude: |

.github/workflows/step-build.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -18,29 +18,29 @@ jobs:
1818
run: |
1919
echo "Branch: ${{ inputs.checkout-ref }}"
2020
- name: Checkout
21-
uses: actions/checkout@v5
21+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
2222
with:
2323
ref: ${{ inputs.checkout-ref }}
2424
- name: Setup .NET Core
25-
uses: actions/setup-dotnet@v5.0.0
25+
uses: actions/setup-dotnet@d4c94342e560b34958eacfc5d055d21461ed1c5d
2626
with:
2727
dotnet-version: 9.0.x
2828
- name: Restore
29-
uses: cake-build/cake-action@v3
29+
uses: cake-build/cake-action@5167c3f6a9e15c76f009de2acdfb9488552bc0b9
3030
with:
3131
target: Restore
3232
- name: Build
33-
uses: cake-build/cake-action@v3
33+
uses: cake-build/cake-action@5167c3f6a9e15c76f009de2acdfb9488552bc0b9
3434
with:
3535
target: Build
3636
arguments: |
3737
versionNumber: ${{inputs.version}}
3838
- name: Run tests
39-
uses: cake-build/cake-action@v3
39+
uses: cake-build/cake-action@5167c3f6a9e15c76f009de2acdfb9488552bc0b9
4040
with:
4141
target: Test
4242
- name: Publish Unit Test Results
4343
if: ${{ github.actor != 'dependabot[bot]' }}
44-
uses: EnricoMi/publish-unit-test-result-action/linux@v2
44+
uses: EnricoMi/publish-unit-test-result-action/linux@3a74b2957438d0b6e2e61d67b05318aa25c9e6c6
4545
with:
4646
files: "**/TestResults/*.xml"

.github/workflows/step-push-package.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -15,10 +15,10 @@ jobs:
1515
runs-on: ubuntu-latest
1616
steps:
1717
- name: Checkout
18-
uses: actions/checkout@v4
18+
uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955
1919

2020
- name: Login to GitHub Container Registry
21-
uses: docker/login-action@v2
21+
uses: docker/login-action@465a07811f14bebb1938fbed4728c6a1ff8901fc
2222
with:
2323
registry: ghcr.io
2424
username: ${{ github.actor }}
@@ -31,7 +31,7 @@ jobs:
3131
echo "container_name=$(echo 'SemVer.Action' | tr '[:upper:]' '[:lower:]')" >> $GITHUB_ENV
3232
3333
- name: Build and push Docker image
34-
uses: docker/build-push-action@v2
34+
uses: docker/build-push-action@ac9327eae2b366085ac7f6a2d02df8aa8ead720a
3535
with:
3636
context: .
3737
file: ./src/SemVer.Json/Dockerfile

0 commit comments

Comments
 (0)