3131 persist-credentials : false
3232
3333 - name : Set up .NET
34- uses : actions/setup-dotnet@baa11fbfe1d6520db94683bd5c7a3818018e4309 # v5.1 .0
34+ uses : actions/setup-dotnet@c2fa09f4bde5ebb9d1777cf28262a3eb3db3ced7 # v5.2 .0
3535
3636 - name : Verify format
3737 run : dotnet format --verify-no-changes
@@ -124,10 +124,10 @@ jobs:
124124 fi
125125
126126 - name : Set up .NET
127- uses : actions/setup-dotnet@baa11fbfe1d6520db94683bd5c7a3818018e4309 # v5.1 .0
127+ uses : actions/setup-dotnet@c2fa09f4bde5ebb9d1777cf28262a3eb3db3ced7 # v5.2 .0
128128
129129 - name : Set up Node
130- uses : actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6.2 .0
130+ uses : actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3 .0
131131 with :
132132 cache : " npm"
133133 cache-dependency-path : " **/package-lock.json"
@@ -180,7 +180,7 @@ jobs:
180180
181181 # ######### Registries ##########
182182 - name : Log in to GHCR
183- uses : docker/login-action@b45d80f862d83dbcd57f89517bcf500b2ab88fb2 # v4.0 .0
183+ uses : docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4.1 .0
184184 with :
185185 registry : ghcr.io
186186 username : ${{ github.actor }}
@@ -265,7 +265,7 @@ jobs:
265265
266266 - name : Build Docker image
267267 id : build-artifacts
268- uses : docker/build-push-action@d08e5c354a6adb9ed34480a06d141179aa583294 # v7.0 .0
268+ uses : docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v7.1 .0
269269 with :
270270 context : .
271271 file : ${{ matrix.base_path }}/${{ matrix.project_name }}/Dockerfile
@@ -275,7 +275,7 @@ jobs:
275275
276276 - name : Install Cosign
277277 if : github.event_name != 'pull_request' && env.is_publish_branch == 'true'
278- uses : sigstore/cosign-installer@faadad0cce49287aee09b3a48701e75088a2c6ad # v4.0.0
278+ uses : sigstore/cosign-installer@cad07c2e89fa2edd6e2d7bab4c1aa38e53f76003 # v4.1.1
279279
280280 - name : Sign image with Cosign
281281 if : github.event_name != 'pull_request' && env.is_publish_branch == 'true'
@@ -293,14 +293,14 @@ jobs:
293293
294294 - name : Scan Docker image
295295 id : container-scan
296- uses : anchore/scan-action@7037fa011853d5a11690026fb85feee79f4c946c # v7.3.2
296+ uses : anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 # v7.4.0
297297 with :
298298 image : ${{ steps.image-tags.outputs.primary_tag }}
299299 fail-build : false
300300 output-format : sarif
301301
302302 - name : Upload Grype results to GitHub
303- uses : github/codeql-action/upload-sarif@cdefb33c0f6224e58673d9004f47f7cb3e328b89 # v4.31.10
303+ uses : github/codeql-action/upload-sarif@95e58e9a2cdfd71adc6e0353d5c52f41a045d225 # v4.35.2
304304 with :
305305 sarif_file : ${{ steps.container-scan.outputs.sarif }}
306306 sha : ${{ contains(github.event_name, 'pull_request') && github.event.pull_request.head.sha || github.sha }}
@@ -327,10 +327,10 @@ jobs:
327327 persist-credentials : false
328328
329329 - name : Set up .NET
330- uses : actions/setup-dotnet@baa11fbfe1d6520db94683bd5c7a3818018e4309 # v5.1 .0
330+ uses : actions/setup-dotnet@c2fa09f4bde5ebb9d1777cf28262a3eb3db3ced7 # v5.2 .0
331331
332332 - name : Log in to GHCR
333- uses : docker/login-action@b45d80f862d83dbcd57f89517bcf500b2ab88fb2 # v4.0 .0
333+ uses : docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4.1 .0
334334 with :
335335 registry : ghcr.io
336336 username : ${{ github.actor }}
@@ -450,7 +450,7 @@ jobs:
450450 persist-credentials : false
451451
452452 - name : Set up .NET
453- uses : actions/setup-dotnet@baa11fbfe1d6520db94683bd5c7a3818018e4309 # v5.1 .0
453+ uses : actions/setup-dotnet@c2fa09f4bde5ebb9d1777cf28262a3eb3db3ced7 # v5.2 .0
454454
455455 - name : Print environment
456456 run : |
@@ -506,7 +506,7 @@ jobs:
506506 uses : bitwarden/gh-actions/azure-logout@main
507507
508508 - name : Generate GH App token
509- uses : actions/create-github-app-token@f8d387b68d61c58ab83c6c016672934102569859 # v3.0.0
509+ uses : actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1
510510 id : app-token
511511 with :
512512 app-id : ${{ steps.get-kv-secrets.outputs.BW-GHAPP-ID }}
@@ -555,7 +555,7 @@ jobs:
555555 uses : bitwarden/gh-actions/azure-logout@main
556556
557557 - name : Generate GH App token
558- uses : actions/create-github-app-token@f8d387b68d61c58ab83c6c016672934102569859 # v3.0.0
558+ uses : actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1
559559 id : app-token
560560 with :
561561 app-id : ${{ steps.get-kv-secrets.outputs.BW-GHAPP-ID }}
@@ -635,7 +635,7 @@ jobs:
635635 uses : bitwarden/gh-actions/azure-logout@main
636636
637637 - name : Notify Slack on failure
638- uses : act10ns/slack@44541246747a30eb3102d87f7a4cc5471b0ffb7d # v2.1 .0
638+ uses : act10ns/slack@d96404edccc6d6467fc7f8134a420c851b1e9054 # v2.2 .0
639639 if : failure()
640640 env :
641641 SLACK_WEBHOOK_URL : ${{ steps.retrieve-secrets.outputs.devops-alerts-slack-webhook-url }}
0 commit comments