Skip to content

Commit 05d4af1

Browse files
authored
chore(deps): pin dependencies (#432)
Co-authored-by: descope[bot] <107609351+descope[bot]@users.noreply.github.com>
1 parent ac735c3 commit 05d4af1

File tree

5 files changed

+16
-16
lines changed

5 files changed

+16
-16
lines changed

.github/actions/setup/action.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,14 +11,14 @@ runs:
1111
using: composite
1212
steps:
1313
- name: Setup Node.js 🔠
14-
uses: actions/setup-node@v4
14+
uses: actions/setup-node@1d0ff469b7ec7b3cb9d8673fde0c81c44821de2a # v4
1515
with:
1616
node-version: ${{ inputs.node_version }}
1717
env:
1818
NODE_AUTH_TOKEN: ${{ inputs.token }}
1919

2020
- name: Cache node modules 💸
21-
uses: actions/cache@v4
21+
uses: actions/cache@1bd1e32a3bdc45362d1e726936510720a7c30a57 # v4
2222
env:
2323
NODE_AUTH_TOKEN: ${{ inputs.token }}
2424
cache-name: cache-node-modules

.github/workflows/ci.yml

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -15,8 +15,8 @@ jobs:
1515
runs-on: ubuntu-latest
1616
steps:
1717
- name: Checkout code
18-
uses: actions/checkout@v4
19-
- uses: actions/setup-node@v4
18+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
19+
- uses: actions/setup-node@1d0ff469b7ec7b3cb9d8673fde0c81c44821de2a # v4
2020
with:
2121
node-version: ${{ env.NODE_VERSION }}
2222
# Skip post-install scripts here, as a malicious
@@ -42,8 +42,8 @@ jobs:
4242
runs-on: ubuntu-latest
4343
steps:
4444
- name: Checkout code
45-
uses: actions/checkout@v4
46-
- uses: actions/setup-node@v4
45+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
46+
- uses: actions/setup-node@1d0ff469b7ec7b3cb9d8673fde0c81c44821de2a # v4
4747
with:
4848
node-version: ${{ env.NODE_VERSION }}
4949
# Skip post-install scripts here, as a malicious
@@ -61,8 +61,8 @@ jobs:
6161
runs-on: ubuntu-latest
6262
steps:
6363
- name: Checkout code
64-
uses: actions/checkout@v4
65-
- uses: actions/setup-node@v4
64+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
65+
- uses: actions/setup-node@1d0ff469b7ec7b3cb9d8673fde0c81c44821de2a # v4
6666
with:
6767
node-version: ${{ env.NODE_VERSION }}
6868
# Skip post-install scripts here, as a malicious
@@ -84,8 +84,8 @@ jobs:
8484
version: [12, 14, 16, 18]
8585
steps:
8686
- name: Checkout code
87-
uses: actions/checkout@v4
88-
- uses: actions/setup-node@v4
87+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
88+
- uses: actions/setup-node@1d0ff469b7ec7b3cb9d8673fde0c81c44821de2a # v4
8989
with:
9090
node-version: ${{ env.NODE_VERSION }}
9191
# Skip post-install scripts here, as a malicious

.github/workflows/publish-next.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,11 +17,11 @@ jobs:
1717
runs-on: ubuntu-latest
1818

1919
steps:
20-
- uses: actions/checkout@v4
20+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
2121
with:
2222
persist-credentials: false # otherwise, the token used is the GITHUB_TOKEN, instead of your personal token
2323
fetch-depth: 0 # otherwise, you will failed to push refs to dest repo
24-
- uses: actions/setup-node@v4
24+
- uses: actions/setup-node@1d0ff469b7ec7b3cb9d8673fde0c81c44821de2a # v4
2525
with:
2626
node-version: ${{ env.NODE_VERSION }}
2727
registry-url: https://registry.npmjs.org/

.github/workflows/publish.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,8 +17,8 @@ jobs:
1717
runs-on: ubuntu-latest
1818

1919
steps:
20-
- uses: actions/checkout@v4
21-
- uses: actions/setup-node@v4
20+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
21+
- uses: actions/setup-node@1d0ff469b7ec7b3cb9d8673fde0c81c44821de2a # v4
2222
with:
2323
node-version: ${{ env.NODE_VERSION }}
2424
registry-url: https://registry.npmjs.org/

.github/workflows/release.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ jobs:
1313
if: "contains(github.event.head_commit.message, 'RELEASE')"
1414
steps:
1515
- name: Checkout source code
16-
uses: actions/checkout@v4
16+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
1717
with:
1818
persist-credentials: false
1919
ref: ${{ github.ref }}
@@ -22,7 +22,7 @@ jobs:
2222

2323
- name: Get token
2424
id: get_token
25-
uses: tibdex/github-app-token@v2
25+
uses: tibdex/github-app-token@3beb63f4bd073e61482598c45c71c1019b59b73a # v2
2626
with:
2727
private_key: ${{ secrets.RELEASE_APP_PEM }}
2828
app_id: ${{ secrets.RELEASE_APP_ID }}

0 commit comments

Comments
 (0)