Skip to content

Commit 320e783

Browse files
committed
Use full semver to pin actions/github-script
Change-type: patch Signed-off-by: Kyle Harding <[email protected]>
1 parent ae48df8 commit 320e783

File tree

1 file changed

+26
-26
lines changed

1 file changed

+26
-26
lines changed

flowzone.yml

Lines changed: 26 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -75,7 +75,7 @@
7575
TAG: ${{ steps.versionist.outputs.tag }}
7676
MESSAGE: ${{ steps.versionist.outputs.tag }}
7777
SHA: ${{ steps.create_commit.outputs.sha }}
78-
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
78+
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
7979
with:
8080
github-token: ${{ steps.gh_app_token.outputs.token || secrets.FLOWZONE_TOKEN }}
8181
result-encoding: json
@@ -98,7 +98,7 @@
9898
env:
9999
REF: "heads/${{ github.base_ref }}"
100100
SHA: ${{ steps.create_commit.outputs.sha }}
101-
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
101+
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
102102
with:
103103
github-token: ${{ steps.gh_app_token.outputs.token || secrets.FLOWZONE_TOKEN }}
104104
result-encoding: json
@@ -118,7 +118,7 @@
118118
env:
119119
REF: "refs/tags/${{ steps.versionist.outputs.tag }}"
120120
SHA: ${{ steps.create_tag.outputs.sha }}
121-
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
121+
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
122122
with:
123123
github-token: ${{ steps.gh_app_token.outputs.token || secrets.FLOWZONE_TOKEN }}
124124
result-encoding: json
@@ -338,7 +338,7 @@
338338

339339
- &jsonArrayBuilder
340340
name: Build JSON list from comma-separated input
341-
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
341+
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
342342
with:
343343
result-encoding: json
344344
script: |
@@ -350,7 +350,7 @@
350350
351351
- &newlineListBuilder
352352
name: Build newline-separated list from JSON list input
353-
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
353+
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
354354
with:
355355
result-encoding: string
356356
script: |
@@ -374,7 +374,7 @@
374374
375375
- &sanitizeDockerStrings
376376
name: Sanitize docker strings
377-
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
377+
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
378378
id: strings
379379
env:
380380
TARGET: ${{ matrix.target }}
@@ -543,7 +543,7 @@
543543
# https://octokit.github.io/rest.js/v21/#pulls-list-commits
544544
name: Reject HEAD branches containing merge commits
545545
if: github.event.pull_request.state == 'open'
546-
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
546+
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
547547
with:
548548
github-token: ${{ steps.gh_app_token.outputs.token || secrets.FLOWZONE_TOKEN }}
549549
result-encoding: json
@@ -567,7 +567,7 @@
567567
# This check passes when the PR is open too, but only on pull_request events and not pull_request_target.
568568
# So only check on merged PRs where the HEAD sha should always be a parent of the merge commit.
569569
if: github.event.pull_request.merged
570-
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
570+
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
571571
with:
572572
github-token: ${{ steps.gh_app_token.outputs.token || secrets.FLOWZONE_TOKEN }}
573573
result-encoding: json
@@ -1168,7 +1168,7 @@ jobs:
11681168
- *rejectNonLinearMerge
11691169

11701170
- name: Check for legacy branch protection
1171-
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
1171+
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
11721172
if: inputs.app_id && inputs.disable_versioning != true && github.event.pull_request.state == 'open'
11731173
with:
11741174
github-token: ${{ steps.gh_app_token.outputs.token || secrets.FLOWZONE_TOKEN }}
@@ -1232,7 +1232,7 @@ jobs:
12321232
12331233
# https://github.com/actions/github-script
12341234
- name: Run balena-versionist
1235-
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
1235+
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
12361236
if: inputs.disable_versioning != true
12371237
id: versionist
12381238
env:
@@ -1268,7 +1268,7 @@ jobs:
12681268
id: create_tree
12691269
env:
12701270
PARENT_COMMIT_SHA: ${{ steps.git_describe.outputs.sha }}
1271-
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
1271+
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
12721272
with:
12731273
github-token: ${{ steps.gh_app_token.outputs.token || secrets.FLOWZONE_TOKEN }}
12741274
script: |
@@ -1332,7 +1332,7 @@ jobs:
13321332
MESSAGE: ${{ steps.versionist.outputs.tag }}
13331333
TREE_SHA: ${{ steps.create_tree.outputs.sha }}
13341334
PARENT_COMMIT_SHA: ${{ steps.git_describe.outputs.sha }}
1335-
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
1335+
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
13361336
with:
13371337
github-token: ${{ steps.gh_app_token.outputs.token || secrets.FLOWZONE_TOKEN }}
13381338
result-encoding: json
@@ -1502,7 +1502,7 @@ jobs:
15021502
# https://docs.github.com/en/rest/commits/commits#compare-two-commits
15031503
- name: Generate short release note
15041504
id: short_release_notes
1505-
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
1505+
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
15061506
env:
15071507
USER_DEFINED: ${{ steps.format_release_notes.outputs.body }}
15081508
CURRENT_TAG: ${{ needs.versioned_source.outputs.tag }}
@@ -1809,7 +1809,7 @@ jobs:
18091809
# https://octokit.github.io/rest.js/v21/#code-scanning-upload-sarif
18101810
# https://github.com/github/codeql-action/issues/2654
18111811
- name: Upload SARIF file to GitHub
1812-
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
1812+
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
18131813
# For now let's just continue on error as this is not a critical path
18141814
continue-on-error: true
18151815
env:
@@ -1862,7 +1862,7 @@ jobs:
18621862
# https://octokit.github.io/rest.js/v21/#repos-get-content
18631863
- name: List files in project root
18641864
id: project-root
1865-
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
1865+
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
18661866
with:
18671867
github-token: ${{ github.token }}
18681868
result-encoding: json
@@ -1887,7 +1887,7 @@ jobs:
18871887
if: inputs.working_directory && inputs.working_directory != '.'
18881888
env:
18891889
WORKING_DIRECTORY: ${{ inputs.working_directory }}
1890-
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
1890+
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
18911891
with:
18921892
github-token: ${{ github.token }}
18931893
result-encoding: json
@@ -1989,7 +1989,7 @@ jobs:
19891989
- *shallowCheckout
19901990

19911991
- name: Process package.json
1992-
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
1992+
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
19931993
id: package_json
19941994
with:
19951995
result-encoding: json
@@ -2054,7 +2054,7 @@ jobs:
20542054
# Default to 20.x if no versions were matched
20552055
# https://github.com/actions/github-script
20562056
- name: Set Node.js versions
2057-
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
2057+
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
20582058
id: node_versions
20592059
env:
20602060
# Tested that this will always return a JSON array.
@@ -2137,7 +2137,7 @@ jobs:
21372137
# in this custom bake json we also set some default cache values, and inherit the docker-metadata-action
21382138
- name: Pre-process Docker bake files
21392139
id: docker_bake
2140-
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
2140+
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
21412141
env:
21422142
TEMP_BAKE_FILE: ${{ runner.temp }}/docker-bake.json
21432143
BAKE_TARGETS: ${{ inputs.bake_targets }}
@@ -2262,7 +2262,7 @@ jobs:
22622262
- name: Build docker test matrix
22632263
id: docker_test
22642264
if: steps.docker_bake.outputs.result != ''
2265-
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
2265+
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
22662266
env:
22672267
<<: *dockerPlatformSlugMap
22682268
BAKE_JSON: "${{ steps.docker_bake.outputs.result }}"
@@ -2335,7 +2335,7 @@ jobs:
23352335
inputs.docker_images != '' &&
23362336
join(fromJSON(steps.docker_bake.outputs.targets)) != '' &&
23372337
steps.docker_bake.outputs.result != ''
2338-
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
2338+
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
23392339
env:
23402340
<<: *dockerPlatformSlugMap
23412341
BAKE_JSON: ${{ steps.docker_bake.outputs.result }}
@@ -2708,7 +2708,7 @@ jobs:
27082708
contains(needs.file_list.outputs.workdir, 'aws-cf-templates.yaml') ||
27092709
contains(needs.file_list.outputs.workdir, 'aws-cf-templates.yml') ||
27102710
contains(needs.file_list.outputs.workdir, 'aws-cf-templates.json')
2711-
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
2711+
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
27122712
with:
27132713
result-encoding: json
27142714
script: |
@@ -2755,7 +2755,7 @@ jobs:
27552755
- name: Validate CloudFormation input
27562756
id: validate_input
27572757
if: inputs.cloudformation_templates != '' && steps.validate_files.outputs.enabled != 'true'
2758-
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
2758+
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
27592759
with:
27602760
result-encoding: json
27612761
script: |
@@ -2792,7 +2792,7 @@ jobs:
27922792
- name: Generate stacks matrix
27932793
id: cloudformation_stacks
27942794
if: steps.validate_files.outputs.enabled == 'true' || steps.validate_input.outputs.enabled == 'true'
2795-
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
2795+
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
27962796
env:
27972797
BASE_SHA: ${{ github.event.pull_request.base.sha }}
27982798
HEAD_SHA: ${{ github.event.pull_request.head.sha || github.event.head_commit.id }}
@@ -5007,7 +5007,7 @@ jobs:
50075007
# Get the current state of the PR so we can check if it is in draft state
50085008
- name: Get the PR state
50095009
id: get-pr
5010-
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
5010+
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
50115011
with:
50125012
result-encoding: json
50135013
github-token: "${{ steps.gh_app_token.outputs.token || secrets.FLOWZONE_TOKEN }}"
@@ -5029,7 +5029,7 @@ jobs:
50295029
- name: Check if branch has rules
50305030
if: ${{ fromJSON(steps.get-pr.outputs.result).draft == false }}
50315031
id: get-branch-rules
5032-
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
5032+
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
50335033
with:
50345034
result-encoding: json
50355035
github-token: "${{ steps.gh_app_token.outputs.token || secrets.FLOWZONE_TOKEN }}"

0 commit comments

Comments
 (0)