diff --git a/.github/workflows/auto-approver.yaml b/.github/workflows/auto-approver.yaml index 5daee84..74302bf 100644 --- a/.github/workflows/auto-approver.yaml +++ b/.github/workflows/auto-approver.yaml @@ -10,7 +10,7 @@ jobs: autoapprove: runs-on: ubuntu-22.04 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4 - name: Approve PR run: | gh pr review --approve || true diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml index 0e46f89..bf50d1f 100644 --- a/.github/workflows/build.yaml +++ b/.github/workflows/build.yaml @@ -8,7 +8,7 @@ jobs: runs-on: ubuntu-22.04 steps: - name: Checkout repository - uses: actions/checkout@v4 + uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4 - name: Get name id: name @@ -25,12 +25,12 @@ jobs: run: syft ${{ steps.rockcraft.outputs.rock }} -o spdx-json=${{ steps.name.outputs.name }}.sbom.json - name: Upload SBOM - uses: actions/upload-artifact@v3 + uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3 with: name: ${{ steps.name.outputs.name }}-sbom path: "${{ steps.name.outputs.name }}.sbom.json" - - uses: actions/upload-artifact@v3 + - uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3 with: name: rock path: ${{ steps.rockcraft.outputs.rock }} diff --git a/.github/workflows/lint.yaml b/.github/workflows/lint.yaml index bb1227b..c6634ee 100644 --- a/.github/workflows/lint.yaml +++ b/.github/workflows/lint.yaml @@ -16,7 +16,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout repository - uses: actions/checkout@v4 + uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4 - name: Install yamllint run: python3 -m pip install yamllint diff --git a/.github/workflows/publish.yaml b/.github/workflows/publish.yaml index d4d2936..7a7ed32 100644 --- a/.github/workflows/publish.yaml +++ b/.github/workflows/publish.yaml @@ -8,7 +8,7 @@ jobs: runs-on: ubuntu-22.04 steps: - name: Checkout repository - uses: actions/checkout@v4 + uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4 - name: Log in to the Container registry uses: docker/login-action@b4bedf8053341df3b5a9f9e0f2cf4e79e27360c6 @@ -25,7 +25,7 @@ jobs: run: | sudo snap install yq - - uses: actions/download-artifact@v3 + - uses: actions/download-artifact@9bc31d5ccc31df68ecc42ccf4149144866c47d8a # v3 with: name: rock diff --git a/.github/workflows/scan.yaml b/.github/workflows/scan.yaml index 2f55d12..d05365d 100644 --- a/.github/workflows/scan.yaml +++ b/.github/workflows/scan.yaml @@ -8,7 +8,7 @@ jobs: runs-on: ubuntu-22.04 steps: - name: Checkout repository - uses: actions/checkout@v4 + uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4 - name: Get name and version id: image_info @@ -24,6 +24,6 @@ jobs: output: 'trivy-results.sarif' - name: Upload scan results to GitHub - uses: github/codeql-action/upload-sarif@v2 + uses: github/codeql-action/upload-sarif@3e0e84636c6f5df46a2cb232ae1dd1384713150d # v2 with: sarif_file: 'trivy-results.sarif'