Skip to content

Commit 8fa2741

Browse files
authored
build(.github): pin actions to commit-hash (#153)
1 parent b545e32 commit 8fa2741

11 files changed

+78
-78
lines changed

.github/workflows/plugins-benchmark-pr.yml

+4-4
Original file line numberDiff line numberDiff line change
@@ -56,13 +56,13 @@ jobs:
5656
node-version: ${{ fromJson(inputs.node-versions) }}
5757
steps:
5858
- name: Checkout ${{ inputs.pr-repo }}@${{ inputs.pr-ref }}
59-
uses: actions/checkout@v4
59+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
6060
with:
6161
persist-credentials: false
6262
ref: ${{ inputs.pr-sha }}
6363
repository: ${{ inputs.pr-repo }}
6464

65-
- uses: actions/setup-node@v4
65+
- uses: actions/setup-node@cdca7365b2dadb8aad0a33bc7601856ffabcc48e # v4.3.0
6666
with:
6767
check-latest: true
6868
node-version: ${{ matrix.node-version }}
@@ -79,7 +79,7 @@ jobs:
7979
echo 'EOF' >> $GITHUB_OUTPUT
8080
8181
- name: Checkout ${{ inputs.base-repo }}@${{ inputs.base-ref }}
82-
uses: actions/checkout@v4
82+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
8383
with:
8484
persist-credentials: false
8585
ref: ${{ inputs.base-sha }}
@@ -103,7 +103,7 @@ jobs:
103103
pull-requests: write
104104
steps:
105105
- name: Comment PR
106-
uses: thollander/actions-comment-pull-request@v3
106+
uses: thollander/actions-comment-pull-request@65f9e5c9a1f2cd378bd74b2e057c9736982a8e74 # v3
107107
with:
108108
github-token: ${{ secrets.GITHUB_TOKEN }}
109109
message: |

.github/workflows/plugins-ci-elasticsearch.yml

+9-9
Original file line numberDiff line numberDiff line change
@@ -43,12 +43,12 @@ jobs:
4343
contents: read
4444
steps:
4545
- name: Check out repo
46-
uses: actions/checkout@v4
46+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
4747
with:
4848
persist-credentials: false
4949

5050
- name: Dependency review
51-
uses: actions/dependency-review-action@v4
51+
uses: actions/dependency-review-action@3b139cfc5fae8b618d3eae3675e383bb1769c019 # v4.5.0
5252

5353
license-check:
5454
if: >
@@ -60,12 +60,12 @@ jobs:
6060
permissions:
6161
contents: read
6262
steps:
63-
- uses: actions/checkout@v4
63+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
6464
with:
6565
persist-credentials: false
6666

6767
- name: Setup Node
68-
uses: actions/setup-node@v4
68+
uses: actions/setup-node@cdca7365b2dadb8aad0a33bc7601856ffabcc48e # v4.3.0
6969
with:
7070
check-latest: true
7171
node-version: lts/*
@@ -87,12 +87,12 @@ jobs:
8787
contents: read
8888
steps:
8989
- name: Check out repo
90-
uses: actions/checkout@v4
90+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
9191
with:
9292
persist-credentials: false
9393

9494
- name: Setup Node
95-
uses: actions/setup-node@v4
95+
uses: actions/setup-node@cdca7365b2dadb8aad0a33bc7601856ffabcc48e # v4.3.0
9696
with:
9797
check-latest: true
9898
node-version: lts/*
@@ -123,12 +123,12 @@ jobs:
123123
124124
steps:
125125
- name: Check out repo
126-
uses: actions/checkout@v4
126+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
127127
with:
128128
persist-credentials: false
129129

130130
- name: Setup Node ${{ matrix.node-version }}
131-
uses: actions/setup-node@v4
131+
uses: actions/setup-node@cdca7365b2dadb8aad0a33bc7601856ffabcc48e # v4.3.0
132132
with:
133133
check-latest: true
134134
node-version: ${{ matrix.node-version }}
@@ -150,7 +150,7 @@ jobs:
150150
contents: write
151151
runs-on: ubuntu-latest
152152
steps:
153-
- uses: fastify/github-action-merge-dependabot@v3
153+
- uses: fastify/github-action-merge-dependabot@e820d631adb1d8ab16c3b93e5afe713450884a4a # v3.11.1
154154
with:
155155
exclude: ${{ inputs.auto-merge-exclude }}
156156
github-token: ${{ secrets.GITHUB_TOKEN }}

.github/workflows/plugins-ci-kafka.yml

+9-9
Original file line numberDiff line numberDiff line change
@@ -38,12 +38,12 @@ jobs:
3838
contents: read
3939
steps:
4040
- name: Check out repo
41-
uses: actions/checkout@v4
41+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
4242
with:
4343
persist-credentials: false
4444

4545
- name: Dependency review
46-
uses: actions/dependency-review-action@v4
46+
uses: actions/dependency-review-action@3b139cfc5fae8b618d3eae3675e383bb1769c019 # v4.5.0
4747

4848
license-check:
4949
if: >
@@ -55,12 +55,12 @@ jobs:
5555
permissions:
5656
contents: read
5757
steps:
58-
- uses: actions/checkout@v4
58+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
5959
with:
6060
persist-credentials: false
6161

6262
- name: Setup Node
63-
uses: actions/setup-node@v4
63+
uses: actions/setup-node@cdca7365b2dadb8aad0a33bc7601856ffabcc48e # v4.3.0
6464
with:
6565
check-latest: true
6666
node-version: lts/*
@@ -82,12 +82,12 @@ jobs:
8282
contents: read
8383
steps:
8484
- name: Check out repo
85-
uses: actions/checkout@v4
85+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
8686
with:
8787
persist-credentials: false
8888

8989
- name: Setup Node
90-
uses: actions/setup-node@v4
90+
uses: actions/setup-node@cdca7365b2dadb8aad0a33bc7601856ffabcc48e # v4.3.0
9191
with:
9292
check-latest: true
9393
node-version: lts/*
@@ -127,12 +127,12 @@ jobs:
127127
128128
steps:
129129
- name: Check out repo
130-
uses: actions/checkout@v4
130+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
131131
with:
132132
persist-credentials: false
133133

134134
- name: Setup Node ${{ matrix.node-version }}
135-
uses: actions/setup-node@v4
135+
uses: actions/setup-node@cdca7365b2dadb8aad0a33bc7601856ffabcc48e # v4.3.0
136136
with:
137137
check-latest: true
138138
node-version: ${{ matrix.node-version }}
@@ -154,7 +154,7 @@ jobs:
154154
contents: write
155155
runs-on: ubuntu-latest
156156
steps:
157-
- uses: fastify/github-action-merge-dependabot@v3
157+
- uses: fastify/github-action-merge-dependabot@e820d631adb1d8ab16c3b93e5afe713450884a4a # v3.11.1
158158
with:
159159
exclude: ${{ inputs.auto-merge-exclude }}
160160
github-token: ${{ secrets.GITHUB_TOKEN }}

.github/workflows/plugins-ci-mongo.yml

+9-9
Original file line numberDiff line numberDiff line change
@@ -38,12 +38,12 @@ jobs:
3838
contents: read
3939
steps:
4040
- name: Check out repo
41-
uses: actions/checkout@v4
41+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
4242
with:
4343
persist-credentials: false
4444

4545
- name: Dependency review
46-
uses: actions/dependency-review-action@v4
46+
uses: actions/dependency-review-action@3b139cfc5fae8b618d3eae3675e383bb1769c019 # v4.5.0
4747

4848
license-check:
4949
if: >
@@ -55,12 +55,12 @@ jobs:
5555
permissions:
5656
contents: read
5757
steps:
58-
- uses: actions/checkout@v4
58+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
5959
with:
6060
persist-credentials: false
6161

6262
- name: Setup Node
63-
uses: actions/setup-node@v4
63+
uses: actions/setup-node@cdca7365b2dadb8aad0a33bc7601856ffabcc48e # v4.3.0
6464
with:
6565
check-latest: true
6666
node-version: lts/*
@@ -82,12 +82,12 @@ jobs:
8282
contents: read
8383
steps:
8484
- name: Check out repo
85-
uses: actions/checkout@v4
85+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
8686
with:
8787
persist-credentials: false
8888

8989
- name: Setup Node
90-
uses: actions/setup-node@v4
90+
uses: actions/setup-node@cdca7365b2dadb8aad0a33bc7601856ffabcc48e # v4.3.0
9191
with:
9292
check-latest: true
9393
node-version: lts/*
@@ -115,12 +115,12 @@ jobs:
115115

116116
steps:
117117
- name: Check out repo
118-
uses: actions/checkout@v4
118+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
119119
with:
120120
persist-credentials: false
121121

122122
- name: Setup Node ${{ matrix.node-version }}
123-
uses: actions/setup-node@v4
123+
uses: actions/setup-node@cdca7365b2dadb8aad0a33bc7601856ffabcc48e # v4.3.0
124124
with:
125125
check-latest: true
126126
node-version: ${{ matrix.node-version }}
@@ -142,7 +142,7 @@ jobs:
142142
contents: write
143143
runs-on: ubuntu-latest
144144
steps:
145-
- uses: fastify/github-action-merge-dependabot@v3
145+
- uses: fastify/github-action-merge-dependabot@e820d631adb1d8ab16c3b93e5afe713450884a4a # v3.11.1
146146
with:
147147
exclude: ${{ inputs.auto-merge-exclude }}
148148
github-token: ${{ secrets.GITHUB_TOKEN }}

.github/workflows/plugins-ci-mysql.yml

+9-9
Original file line numberDiff line numberDiff line change
@@ -38,12 +38,12 @@ jobs:
3838
contents: read
3939
steps:
4040
- name: Check out repo
41-
uses: actions/checkout@v4
41+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
4242
with:
4343
persist-credentials: false
4444

4545
- name: Dependency review
46-
uses: actions/dependency-review-action@v4
46+
uses: actions/dependency-review-action@3b139cfc5fae8b618d3eae3675e383bb1769c019 # v4.5.0
4747

4848
license-check:
4949
if: >
@@ -55,12 +55,12 @@ jobs:
5555
permissions:
5656
contents: read
5757
steps:
58-
- uses: actions/checkout@v4
58+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
5959
with:
6060
persist-credentials: false
6161

6262
- name: Setup Node
63-
uses: actions/setup-node@v4
63+
uses: actions/setup-node@cdca7365b2dadb8aad0a33bc7601856ffabcc48e # v4.3.0
6464
with:
6565
check-latest: true
6666
node-version: lts/*
@@ -83,12 +83,12 @@ jobs:
8383
steps:
8484

8585
- name: Check out repo
86-
uses: actions/checkout@v4
86+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
8787
with:
8888
persist-credentials: false
8989

9090
- name: Setup Node
91-
uses: actions/setup-node@v4
91+
uses: actions/setup-node@cdca7365b2dadb8aad0a33bc7601856ffabcc48e # v4.3.0
9292
with:
9393
check-latest: true
9494
node-version: lts/*
@@ -123,12 +123,12 @@ jobs:
123123
124124
steps:
125125
- name: Check out repo
126-
uses: actions/checkout@v4
126+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
127127
with:
128128
persist-credentials: false
129129

130130
- name: Setup Node ${{ matrix.node-version }}
131-
uses: actions/setup-node@v4
131+
uses: actions/setup-node@cdca7365b2dadb8aad0a33bc7601856ffabcc48e # v4.3.0
132132
with:
133133
check-latest: true
134134
node-version: ${{ matrix.node-version }}
@@ -150,7 +150,7 @@ jobs:
150150
contents: write
151151
runs-on: ubuntu-latest
152152
steps:
153-
- uses: fastify/github-action-merge-dependabot@v3
153+
- uses: fastify/github-action-merge-dependabot@e820d631adb1d8ab16c3b93e5afe713450884a4a # v3.11.1
154154
with:
155155
exclude: ${{ inputs.auto-merge-exclude }}
156156
github-token: ${{ secrets.GITHUB_TOKEN }}

.github/workflows/plugins-ci-package-manager.yml

+5-5
Original file line numberDiff line numberDiff line change
@@ -21,18 +21,18 @@ jobs:
2121
pnpm-version: [8]
2222
steps:
2323
- name: Check out repo
24-
uses: actions/checkout@v4
24+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
2525
with:
2626
persist-credentials: false
2727

2828
- name: Setup Node ${{ matrix.node-version }}
29-
uses: actions/setup-node@v4
29+
uses: actions/setup-node@cdca7365b2dadb8aad0a33bc7601856ffabcc48e # v4.3.0
3030
with:
3131
check-latest: true
3232
node-version: ${{ matrix.node-version }}
3333

3434
- name: Install with pnpm
35-
uses: pnpm/action-setup@v4
35+
uses: pnpm/action-setup@a7487c7e89a18df4991f7f222e4898a00d66ddda # v4.1.0
3636
with:
3737
version: ${{ matrix.pnpm-version }}
3838

@@ -52,12 +52,12 @@ jobs:
5252
node-version: ${{ fromJson(inputs.node-versions) }}
5353
steps:
5454
- name: Check out repo
55-
uses: actions/checkout@v4
55+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
5656
with:
5757
persist-credentials: false
5858

5959
- name: Setup Node ${{ matrix.node-version }}
60-
uses: actions/setup-node@v4
60+
uses: actions/setup-node@cdca7365b2dadb8aad0a33bc7601856ffabcc48e # v4.3.0
6161
with:
6262
check-latest: true
6363
node-version: ${{ matrix.node-version }}

0 commit comments

Comments
 (0)