Skip to content

Commit 54269ef

Browse files
russellwheatleymikehardy
authored andcommitted
ci: pin GitHub Actions to commit SHAs
1 parent e15b061 commit 54269ef

File tree

3 files changed

+15
-15
lines changed

3 files changed

+15
-15
lines changed

.github/workflows/publish.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,14 +11,14 @@ jobs:
1111
id-token: write # < REQUIRED FOR OIDC
1212

1313
steps:
14-
- uses: actions/checkout@v6
14+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
1515
with:
1616
fetch-depth: 0
1717
- name: git config
1818
run: |
1919
git config --global user.name 'Invertase Publisher'
2020
git config --global user.email 'oss@invertase.io'
21-
- uses: actions/setup-node@v6
21+
- uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6
2222
with:
2323
node-version: "lts/*"
2424
registry-url: "https://registry.npmjs.org"

.github/workflows/test.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -19,34 +19,34 @@ jobs:
1919
timeout-minutes: 15
2020
runs-on: ubuntu-latest
2121
steps:
22-
- uses: actions/checkout@v6
22+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
2323
with:
2424
fetch-depth: 1
25-
- uses: actions/setup-node@v6
25+
- uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6
2626
with:
2727
node-version: 24
2828
- name: Configure JDK
29-
uses: actions/setup-java@v5
29+
uses: actions/setup-java@be666c2fcd27ec809703dec50e508c2fdc7f6654 # v5
3030
with:
3131
distribution: "temurin"
3232
java-version: "25"
33-
- uses: actions/cache/restore@v5
33+
- uses: actions/cache/restore@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5
3434
name: Yarn Cache Restore
3535
id: yarn-cache
3636
with:
3737
path: .yarn/cache
3838
key: ${{ runner.os }}-yarn-v1-${{ hashFiles('yarn.lock') }}
3939
restore-keys: ${{ runner.os }}-yarn-v1
4040
- name: Yarn Install
41-
uses: nick-fields/retry@v3
41+
uses: nick-fields/retry@ce71cc2ab81d554ebbe88c79ab5975992d79ba08 # v3
4242
with:
4343
timeout_minutes: 15
4444
retry_wait_seconds: 30
4545
max_attempts: 3
4646
command: yarn
4747
- name: Lint
4848
run: ./test.sh
49-
- uses: actions/cache/save@v5
49+
- uses: actions/cache/save@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5
5050
name: Yarn Cache Save
5151
if: "${{ github.ref == 'refs/heads/main' }}"
5252
with:

.github/workflows/update-google-java-format.yml

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -20,21 +20,21 @@ jobs:
2020
timeout-minutes: 20
2121

2222
steps:
23-
- uses: actions/checkout@v6
23+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
2424
with:
2525
fetch-depth: 0
2626

27-
- uses: actions/setup-node@v6
27+
- uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6
2828
with:
2929
node-version: 24
3030

3131
- name: Configure JDK
32-
uses: actions/setup-java@v5
32+
uses: actions/setup-java@be666c2fcd27ec809703dec50e508c2fdc7f6654 # v5
3333
with:
3434
distribution: "temurin"
3535
java-version: "25"
3636

37-
- uses: actions/cache/restore@v5
37+
- uses: actions/cache/restore@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5
3838
name: Yarn Cache Restore
3939
id: yarn-cache
4040
with:
@@ -43,7 +43,7 @@ jobs:
4343
restore-keys: ${{ runner.os }}-yarn-v1
4444

4545
- name: Yarn Install
46-
uses: nick-fields/retry@v3
46+
uses: nick-fields/retry@ce71cc2ab81d554ebbe88c79ab5975992d79ba08 # v3
4747
with:
4848
timeout_minutes: 15
4949
retry_wait_seconds: 30
@@ -58,7 +58,7 @@ jobs:
5858
if: steps.update.outputs.updated == 'true'
5959
run: ./test.sh
6060

61-
- uses: actions/cache/save@v5
61+
- uses: actions/cache/save@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5
6262
name: Yarn Cache Save
6363
if: ${{ steps.update.outputs.updated == 'true' && github.ref == 'refs/heads/main' }}
6464
with:
@@ -67,7 +67,7 @@ jobs:
6767

6868
- name: Create pull request
6969
if: steps.update.outputs.updated == 'true'
70-
uses: peter-evans/create-pull-request@v7
70+
uses: peter-evans/create-pull-request@c0f553fe549906ede9cf27b5156039d195d2ece0 # v8.1.0
7171
with:
7272
token: ${{ github.token }}
7373
commit-message: "feat: adopt upstream google-java-format [${{ steps.update.outputs.latest_version }}]"

0 commit comments

Comments
 (0)