Skip to content

Commit 08f55e0

Browse files
authored
Pin GitHub Actions (#745)
Pin GitHub Actions Co-authored-by: julien.doutre <julien.doutre@datadoghq.com>
1 parent c8ee93b commit 08f55e0

4 files changed

Lines changed: 18 additions & 18 deletions

File tree

.github/workflows/build.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -11,10 +11,10 @@ jobs:
1111
runs-on: ubuntu-latest
1212

1313
steps:
14-
- uses: actions/checkout@v3
14+
- uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # v3.6.0
1515

1616
- name: Set up Node 18.12
17-
uses: actions/setup-node@v3
17+
uses: actions/setup-node@3235b876344d2a9aa001b8d1453c930bba69e610 # v3.9.1
1818
with:
1919
node-version: 18.12
2020

@@ -24,7 +24,7 @@ jobs:
2424

2525
- name: Restore node modules from cache
2626
id: cache-node-modules
27-
uses: actions/cache@v3
27+
uses: actions/cache@6f8efc29b200d32929f49075959781ed54ec270c # v3.5.0
2828
with:
2929
path: ${{ steps.yarn-cache-dir-path.outputs.dir }}
3030
key: ${{ runner.os }}-yarn-${{ hashFiles('**/yarn.lock') }}
@@ -47,10 +47,10 @@ jobs:
4747
node-version: [18.12, 20.19, 22.11, 24.11]
4848
steps:
4949
- name: Checkout
50-
uses: actions/checkout@v3
50+
uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # v3.6.0
5151

5252
- name: Set up Node ${{ matrix.node-version }}
53-
uses: actions/setup-node@v3
53+
uses: actions/setup-node@3235b876344d2a9aa001b8d1453c930bba69e610 # v3.9.1
5454
with:
5555
node-version: ${{ matrix.node-version }}
5656

@@ -60,7 +60,7 @@ jobs:
6060

6161
- name: Restore node modules from cache
6262
id: cache-node-modules
63-
uses: actions/cache@v3
63+
uses: actions/cache@6f8efc29b200d32929f49075959781ed54ec270c # v3.5.0
6464
with:
6565
path: ${{ steps.yarn-cache-dir-path.outputs.dir }}
6666
key: ${{ runner.os }}-yarn-${{ hashFiles('**/yarn.lock') }}

.github/workflows/codeql-analysis.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -38,11 +38,11 @@ jobs:
3838

3939
steps:
4040
- name: Checkout repository
41-
uses: actions/checkout@v3
41+
uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # v3.6.0
4242

4343
# Initializes the CodeQL tools for scanning.
4444
- name: Initialize CodeQL
45-
uses: github/codeql-action/init@v2
45+
uses: github/codeql-action/init@b8d3b6e8af63cde30bdc382c0bc28114f4346c88 # v2.28.1
4646
with:
4747
languages: ${{ matrix.language }}
4848
# If you wish to specify custom queries, you can do so here or in a config file.
@@ -53,7 +53,7 @@ jobs:
5353
# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
5454
# If this step fails, then you should remove it and run the build manually (see below)
5555
- name: Autobuild
56-
uses: github/codeql-action/autobuild@v2
56+
uses: github/codeql-action/autobuild@b8d3b6e8af63cde30bdc382c0bc28114f4346c88 # v2.28.1
5757

5858
# ℹ️ Command-line programs to run using the OS shell.
5959
# 📚 https://git.io/JvXDl
@@ -67,4 +67,4 @@ jobs:
6767
# make release
6868

6969
- name: Perform CodeQL Analysis
70-
uses: github/codeql-action/analyze@v2
70+
uses: github/codeql-action/analyze@b8d3b6e8af63cde30bdc382c0bc28114f4346c88 # v2.28.1

.github/workflows/update-deps.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -18,11 +18,11 @@ jobs:
1818
app-id: ${{ secrets.GH_APP_ID }}
1919
private-key: ${{ secrets.GH_APP_PRIVATE_KEY }}
2020

21-
- uses: actions/checkout@v2
21+
- uses: actions/checkout@ee0669bd1cc54295c223e0bb666b733df41de1c5 # v2.7.0
2222
with:
2323
token: ${{ steps.generate_token.outputs.token }}
2424

25-
- uses: actions/setup-node@v3
25+
- uses: actions/setup-node@3235b876344d2a9aa001b8d1453c930bba69e610 # v3.9.1
2626
with:
2727
node-version: "20.x"
2828

@@ -32,7 +32,7 @@ jobs:
3232
yarn upgrade
3333
3434
- name: Create Pull Request
35-
uses: peter-evans/create-pull-request@v3
35+
uses: peter-evans/create-pull-request@18f7dc018cc2cd597073088f7c7591b9d1c02672 # v3.14.0
3636
with:
3737
token: ${{ steps.generate_token.outputs.token }}
3838
commit-message: update dependencies

.github/workflows/update-snapshots.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -8,16 +8,16 @@ jobs:
88
runs-on: ubuntu-latest
99
steps:
1010
- name: Checkout
11-
uses: actions/checkout@v3
11+
uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # v3.6.0
1212

1313
- name: Set up Node 14
14-
uses: actions/setup-node@v3
14+
uses: actions/setup-node@3235b876344d2a9aa001b8d1453c930bba69e610 # v3.9.1
1515
with:
1616
node-version: 14
1717

1818
- name: Set up Docker Buildx
1919
id: buildx
20-
uses: docker/setup-buildx-action@v2
20+
uses: docker/setup-buildx-action@885d1462b80bc1c1c7f0b00334ad271f09369c55 # v2.10.0
2121

2222
- name: Complete Buildx Setup
2323
run: docker run --privileged --rm tonistiigi/binfmt --install all
@@ -28,7 +28,7 @@ jobs:
2828

2929
- name: Restore node modules from cache
3030
id: cache-node-modules
31-
uses: actions/cache@v3
31+
uses: actions/cache@6f8efc29b200d32929f49075959781ed54ec270c # v3.5.0
3232
with:
3333
path: ${{ steps.yarn-cache-dir-path.outputs.dir }}
3434
key: ${{ runner.os }}-yarn-${{ hashFiles('**/yarn.lock') }}
@@ -52,7 +52,7 @@ jobs:
5252
run: ./scripts/run_integration_tests.sh
5353

5454
- name: Create Pull Request
55-
uses: peter-evans/create-pull-request@v3
55+
uses: peter-evans/create-pull-request@18f7dc018cc2cd597073088f7c7591b9d1c02672 # v3.14.0
5656
with:
5757
commit-message: update snapshots
5858
title: Update Snapshots

0 commit comments

Comments
 (0)