Skip to content

Commit d50b38c

Browse files
authored
Merge pull request #81 from reviewdog/pinact-action-trivy
Pin GitHub Actions with commit SHA using pinact
2 parents 5a2ff86 + a236ab9 commit d50b38c

File tree

5 files changed

+20
-20
lines changed

5 files changed

+20
-20
lines changed

.github/workflows/depup.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -11,17 +11,17 @@ jobs:
1111
runs-on: ubuntu-latest
1212

1313
steps:
14-
- uses: actions/checkout@v4
14+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
1515

16-
- uses: haya14busa/action-depup@v1
16+
- uses: haya14busa/action-depup@d6b40096afad49ca676145faaba7190df29a9807 # v1.6.3
1717
id: depup
1818
with:
1919
file: action.yml
2020
version_name: REVIEWDOG_VERSION
2121
repo: reviewdog/reviewdog
2222

2323
- name: Create Pull Request
24-
uses: peter-evans/create-pull-request@v7
24+
uses: peter-evans/create-pull-request@271a8d0340265f705b14b6d32b9829c1cb33d45e # v7.0.8
2525
with:
2626
token: ${{ secrets.GITHUB_TOKEN }}
2727
title: "chore(deps): update reviewdog to ${{ steps.depup.outputs.latest }}"

.github/workflows/labels.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,6 @@ jobs:
1818
uses: actions/checkout@master
1919

2020
- name: Manage labels
21-
uses: lannonbr/[email protected]
21+
uses: lannonbr/issue-label-manager-action@e8dbcd8198e86a1e98d5372e55db976fed9ba6f7 # 4.0.0
2222
env:
2323
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

.github/workflows/lint.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -11,16 +11,16 @@ jobs:
1111
runs-on: ubuntu-latest
1212

1313
steps:
14-
- uses: actions/checkout@v4
14+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
1515

16-
- uses: haya14busa/action-cond@v1
16+
- uses: haya14busa/action-cond@94f77f7a80cd666cb3155084e428254fea4281fd # v1.2.1
1717
id: reporter
1818
with:
1919
cond: ${{ github.event_name == 'pull_request' }}
2020
if_true: "github-pr-review"
2121
if_false: "github-check"
2222

23-
- uses: reviewdog/action-shellcheck@v1
23+
- uses: reviewdog/action-shellcheck@6e0e63d1750d02d761b3df0f2c5ba9f9ac4a9ed7 # v1.29.0
2424
with:
2525
github_token: ${{ secrets.github_token }}
2626
reporter: ${{ steps.reporter.outputs.value }}
@@ -30,9 +30,9 @@ jobs:
3030
runs-on: ubuntu-latest
3131

3232
steps:
33-
- uses: actions/checkout@v4
33+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
3434

35-
- uses: reviewdog/action-misspell@v1
35+
- uses: reviewdog/action-misspell@18ffb61effb93b47e332f185216be7e49592e7e1 # v1.26.1
3636
with:
3737
github_token: ${{ secrets.github_token }}
3838
reporter: github-check

.github/workflows/release.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -15,24 +15,24 @@ jobs:
1515
runs-on: ubuntu-latest
1616

1717
steps:
18-
- uses: actions/checkout@v4
18+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
1919

2020
# Bump version on merging Pull Requests with specific labels.
2121
# (bump:major,bump:minor,bump:patch)
2222
- id: bumpr
2323
if: "!startsWith(github.ref, 'refs/tags/')"
24-
uses: haya14busa/action-bumpr@v1
24+
uses: haya14busa/action-bumpr@78ab5a104d20896c9c9122c64221b3aecf1a8cbb # v1.10.0
2525

2626
# Update corresponding major and minor tag.
2727
# e.g. Update v1 and v1.2 when releasing v1.2.3
28-
- uses: haya14busa/action-update-semver@v1
28+
- uses: haya14busa/action-update-semver@fb48464b2438ae82cc78237be61afb4f461265a1 # v1.2.1
2929
if: "!steps.bumpr.outputs.skip"
3030
with:
3131
tag: ${{ steps.bumpr.outputs.next_version }}
3232

3333
# Get tag name.
3434
- id: tag
35-
uses: haya14busa/action-cond@v1
35+
uses: haya14busa/action-cond@94f77f7a80cd666cb3155084e428254fea4281fd # v1.2.1
3636
with:
3737
cond: "${{ startsWith(github.ref, 'refs/tags/') }}"
3838
if_true: ${{ github.ref }}
@@ -52,6 +52,6 @@ jobs:
5252
if: github.event.action == 'labeled'
5353
runs-on: ubuntu-latest
5454
steps:
55-
- uses: actions/checkout@v4
55+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
5656
- name: Post bumpr status comment
57-
uses: haya14busa/action-bumpr@v1
57+
uses: haya14busa/action-bumpr@78ab5a104d20896c9c9122c64221b3aecf1a8cbb # v1.10.0

.github/workflows/tests.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ jobs:
1717
matrix: ${{ steps.output-matrix.outputs.matrix }}
1818

1919
steps:
20-
- uses: actions/checkout@v4
20+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
2121
- name: Set up matrix
2222
id: output-matrix
2323
run: |
@@ -45,7 +45,7 @@ jobs:
4545
matrix: ${{ fromJson(needs.setup.outputs.matrix) }}
4646

4747
steps:
48-
- uses: actions/checkout@v4
48+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
4949

5050
- uses: ./
5151
continue-on-error: true
@@ -95,7 +95,7 @@ jobs:
9595
runs-on: ubuntu-latest
9696

9797
steps:
98-
- uses: actions/checkout@v4
98+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
9999

100100
- uses: ./
101101
continue-on-error: true
@@ -135,7 +135,7 @@ jobs:
135135
runs-on: ubuntu-latest
136136

137137
steps:
138-
- uses: actions/checkout@v4
138+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
139139

140140
- uses: ./
141141
continue-on-error: true
@@ -180,7 +180,7 @@ jobs:
180180
runs-on: ${{ matrix.platform }}
181181

182182
steps:
183-
- uses: actions/checkout@v4
183+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
184184

185185
- uses: ./
186186
continue-on-error: true

0 commit comments

Comments
 (0)