Skip to content

Commit 348c0da

Browse files
chore: pin workflows dependencies (#2208)
1 parent 82f1fd3 commit 348c0da

File tree

5 files changed

+31
-30
lines changed

5 files changed

+31
-30
lines changed

.github/renovate.json5

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,8 @@
44
"config:base",
55
"schedule:earlyMondays",
66
"group:allNonMajor",
7-
":prHourlyLimitNone"
7+
":prHourlyLimitNone",
8+
"helpers:pinGitHubActionDigests"
89
],
910
"labels": ["c: dependencies"],
1011
"reviewersFromCodeOwners": true,

.github/workflows/ci.yml

Lines changed: 22 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -35,23 +35,23 @@ jobs:
3535
name: 'Build & Unit Test: node-${{ matrix.node_version }}, ${{ matrix.os }}'
3636
steps:
3737
- name: Checkout
38-
uses: actions/checkout@v3
38+
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
3939
with:
4040
# Required for docs/versions tests
4141
fetch-depth: 0
4242

4343
- name: Install pnpm (node 14, pnpm 7)
4444
if: matrix.node_version == 14
45-
uses: pnpm/[email protected]
45+
uses: pnpm/action-setup@c3b53f6a16e57305370b4ae5a540c2077a1d50dd # v2.2.4
4646
with:
4747
version: 7
4848

4949
- name: Install pnpm
5050
if: matrix.node_version != 14
51-
uses: pnpm/[email protected]
51+
uses: pnpm/action-setup@c3b53f6a16e57305370b4ae5a540c2077a1d50dd # v2.2.4
5252

5353
- name: Set node version to ${{ matrix.node_version }}
54-
uses: actions/setup-node@v3
54+
uses: actions/setup-node@64ed1c7eab4cce3362f8c340dee64e5eaeef8f7c # v3.6.0
5555
with:
5656
node-version: ${{ matrix.node_version }}
5757
cache: 'pnpm'
@@ -90,16 +90,16 @@ jobs:
9090
run: date
9191

9292
- name: Checkout
93-
uses: actions/checkout@v3
93+
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
9494
with:
9595
# Required for docs/versions tests
9696
fetch-depth: 0
9797

9898
- name: Install pnpm
99-
uses: pnpm/[email protected]
99+
uses: pnpm/action-setup@c3b53f6a16e57305370b4ae5a540c2077a1d50dd # v2.2.4
100100

101101
- name: Set node version to ${{ matrix.node_version }}
102-
uses: actions/setup-node@v3
102+
uses: actions/setup-node@64ed1c7eab4cce3362f8c340dee64e5eaeef8f7c # v3.6.0
103103
with:
104104
node-version: ${{ matrix.node_version }}
105105
cache: 'pnpm'
@@ -122,10 +122,10 @@ jobs:
122122
name: 'E2E Doc Test: node-18, ubuntu-latest'
123123
steps:
124124
- name: Checkout
125-
uses: actions/checkout@v3
125+
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
126126

127127
- name: Install pnpm
128-
uses: pnpm/[email protected]
128+
uses: pnpm/action-setup@c3b53f6a16e57305370b4ae5a540c2077a1d50dd # v2.2.4
129129

130130
- name: Install deps
131131
run: pnpm install
@@ -143,15 +143,15 @@ jobs:
143143
name: 'Lint: node-18, ubuntu-latest'
144144
steps:
145145
- name: Checkout
146-
uses: actions/checkout@v3
146+
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
147147
with:
148148
fetch-depth: 0
149149

150150
- name: Install pnpm
151-
uses: pnpm/[email protected]
151+
uses: pnpm/action-setup@c3b53f6a16e57305370b4ae5a540c2077a1d50dd # v2.2.4
152152

153153
- name: Set node version to 18
154-
uses: actions/setup-node@v3
154+
uses: actions/setup-node@64ed1c7eab4cce3362f8c340dee64e5eaeef8f7c # v3.6.0
155155
with:
156156
node-version: 18
157157
cache: 'pnpm'
@@ -173,15 +173,15 @@ jobs:
173173
name: 'TS-Check Scripts: node-18, ubuntu-latest'
174174
steps:
175175
- name: Checkout
176-
uses: actions/checkout@v3
176+
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
177177
with:
178178
fetch-depth: 0
179179

180180
- name: Install pnpm
181-
uses: pnpm/[email protected]
181+
uses: pnpm/action-setup@c3b53f6a16e57305370b4ae5a540c2077a1d50dd # v2.2.4
182182

183183
- name: Set node version to 18
184-
uses: actions/setup-node@v3
184+
uses: actions/setup-node@64ed1c7eab4cce3362f8c340dee64e5eaeef8f7c # v3.6.0
185185
with:
186186
node-version: 18
187187
cache: 'pnpm'
@@ -200,15 +200,15 @@ jobs:
200200
name: 'TS-Check Tests: node-18, ubuntu-latest'
201201
steps:
202202
- name: Checkout
203-
uses: actions/checkout@v3
203+
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
204204
with:
205205
fetch-depth: 0
206206

207207
- name: Install pnpm
208-
uses: pnpm/[email protected]
208+
uses: pnpm/action-setup@c3b53f6a16e57305370b4ae5a540c2077a1d50dd # v2.2.4
209209

210210
- name: Set node version to 18
211-
uses: actions/setup-node@v3
211+
uses: actions/setup-node@64ed1c7eab4cce3362f8c340dee64e5eaeef8f7c # v3.6.0
212212
with:
213213
node-version: 18
214214
cache: 'pnpm'
@@ -227,15 +227,15 @@ jobs:
227227
name: 'Codecov: node-18, ubuntu-latest'
228228
steps:
229229
- name: Checkout
230-
uses: actions/checkout@v3
230+
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
231231
with:
232232
fetch-depth: 0
233233

234234
- name: Install pnpm
235-
uses: pnpm/[email protected]
235+
uses: pnpm/action-setup@c3b53f6a16e57305370b4ae5a540c2077a1d50dd # v2.2.4
236236

237237
- name: Set node version to 18
238-
uses: actions/setup-node@v3
238+
uses: actions/setup-node@64ed1c7eab4cce3362f8c340dee64e5eaeef8f7c # v3.6.0
239239
with:
240240
node-version: 18
241241
cache: 'pnpm'
@@ -252,7 +252,7 @@ jobs:
252252
run: pnpm vitest run --coverage
253253

254254
- name: Upload coverage to Codecov
255-
uses: codecov/[email protected]
255+
uses: codecov/codecov-action@eaaf4bedf32dbdc6b720b63067d99c4d77d6047d # v3.1.4
256256
with:
257257
token: ${{ secrets.CODECOV_TOKEN }}
258258
fail_ci_if_error: true

.github/workflows/comment-issue.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ jobs:
1313
issues: write
1414
steps:
1515
- name: Add Comment For User Interest
16-
uses: actions/github-script@v6
16+
uses: actions/github-script@d7906e4ad0b1822421a7e6a35d5ca353c962f410 # v6.4.1
1717
with:
1818
script: |
1919
github.rest.issues.createComment({
@@ -49,7 +49,7 @@ jobs:
4949
})
5050
5151
- name: React to Issue
52-
uses: actions/github-script@v6
52+
uses: actions/github-script@d7906e4ad0b1822421a7e6a35d5ca353c962f410 # v6.4.1
5353
with:
5454
script: |
5555
github.rest.reactions.createForIssue({

.github/workflows/pr.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -15,15 +15,15 @@ jobs:
1515
pull-requests: write
1616
steps:
1717
- name: Checkout
18-
uses: actions/checkout@v3
18+
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
1919
with:
2020
fetch-depth: 0
2121

2222
- name: Install pnpm
23-
uses: pnpm/[email protected]
23+
uses: pnpm/action-setup@c3b53f6a16e57305370b4ae5a540c2077a1d50dd # v2.2.4
2424

2525
- name: Set node version to 18
26-
uses: actions/setup-node@v3
26+
uses: actions/setup-node@64ed1c7eab4cce3362f8c340dee64e5eaeef8f7c # v3.6.0
2727
with:
2828
node-version: 18
2929
cache: 'pnpm'
@@ -53,7 +53,7 @@ jobs:
5353
run: pnpm exec tsc .github/workflows/commentCodeGeneration.ts --outDir .github/workflows
5454

5555
- name: Comment
56-
uses: actions/github-script@v6
56+
uses: actions/github-script@d7906e4ad0b1822421a7e6a35d5ca353c962f410 # v6.4.1
5757
with:
5858
script: |
5959
const script = require('${{ github.workspace }}/.github/workflows/commentCodeGeneration.js')

.github/workflows/semantic-pull-request.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ jobs:
2020
name: Semantic Pull Request
2121
steps:
2222
- name: Validate PR title
23-
uses: amannn/action-semantic-pull-request@v5
23+
uses: amannn/action-semantic-pull-request@c3cd5d1ea3580753008872425915e343e351ab54 # v5.2.0
2424
env:
2525
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
2626
with:

0 commit comments

Comments
 (0)