Skip to content

Commit 2e92cd2

Browse files
committed
security(ci): pin SHAs
These SHAs came in before the PR to pin SHAs landed Copy/pasted from other files Note: dawidd6/action-download-artifact is now at v21 Issue 21038
1 parent c99b6b5 commit 2e92cd2

2 files changed

Lines changed: 14 additions & 14 deletions

File tree

.github/workflows/screenshot_compare.yml

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -39,23 +39,23 @@ jobs:
3939

4040
steps:
4141
- name: Checkout
42-
uses: actions/checkout@v6
42+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
4343

4444
- name: Configure JDK
45-
uses: actions/setup-java@v5
45+
uses: actions/setup-java@be666c2fcd27ec809703dec50e508c2fdc7f6654 # v5.2.0
4646
with:
4747
distribution: "temurin"
4848
java-version: "21"
4949

5050
- name: Setup Gradle
51-
uses: gradle/actions/setup-gradle@v6
51+
uses: gradle/actions/setup-gradle@50e97c2cd7a37755bbfafc9c5b7cafaece252f6e # v6.1.0
5252
with:
5353
# Use open source provider: https://github.com/gradle/actions/blob/main/docs/setup-gradle.md#basic-caching
5454
cache-provider: basic
5555
gradle-version: wrapper
5656

5757
- name: Download base branch screenshots
58-
uses: dawidd6/action-download-artifact@v3
58+
uses: dawidd6/action-download-artifact@09f2f74827fd3a8607589e5ad7f9398816f540fe # v3.1.4
5959
continue-on-error: true
6060
with:
6161
name: screenshot
@@ -83,15 +83,15 @@ jobs:
8383
done
8484
8585
- name: Upload screenshot diffs
86-
uses: actions/upload-artifact@v4
86+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
8787
if: ${{ always() }}
8888
with:
8989
name: screenshot-diff # referenced by screenshot_comment.yml
9090
path: screenshot-diff
9191
retention-days: 30
9292

9393
- name: Upload screenshot diff reports
94-
uses: actions/upload-artifact@v4
94+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
9595
if: ${{ always() }}
9696
with:
9797
name: screenshot-diff-reports
@@ -100,7 +100,7 @@ jobs:
100100
retention-days: 30
101101

102102
- name: Upload screenshot diff test results
103-
uses: actions/upload-artifact@v4
103+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
104104
if: ${{ always() }}
105105
with:
106106
name: screenshot-diff-test-results
@@ -114,7 +114,7 @@ jobs:
114114
mkdir -p ./pr
115115
echo ${{ github.event.number }} > ./pr/NR
116116
- name: Persist PR number
117-
uses: actions/upload-artifact@v4
117+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
118118
with:
119119
name: pr # downloaded by screenshot_comment.yml
120120
path: pr/

.github/workflows/screenshot_store.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -51,17 +51,17 @@ jobs:
5151

5252
steps:
5353
- name: Checkout
54-
uses: actions/checkout@v6
54+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
5555

5656
- name: Configure JDK
57-
uses: actions/setup-java@v5
57+
uses: actions/setup-java@be666c2fcd27ec809703dec50e508c2fdc7f6654 # v5.2.0
5858
with:
5959
distribution: "temurin"
6060
java-version: "21"
6161

6262
# Better than caching and/or extensions of actions/setup-java
6363
- name: Setup Gradle
64-
uses: gradle/actions/setup-gradle@v6
64+
uses: gradle/actions/setup-gradle@50e97c2cd7a37755bbfafc9c5b7cafaece252f6e # v6.1.0
6565
with:
6666
# Use open source provider: https://github.com/gradle/actions/blob/main/docs/setup-gradle.md#basic-caching
6767
cache-provider: basic
@@ -74,7 +74,7 @@ jobs:
7474
./gradlew recordRoborazziPlayDebug -Pscreenshot --stacktrace --rerun-tasks
7575
7676
- name: Upload screenshot baseline
77-
uses: actions/upload-artifact@v4
77+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
7878
if: ${{ always() }}
7979
with:
8080
name: screenshot # downloaded by screenshot_compare.yml
@@ -83,7 +83,7 @@ jobs:
8383
retention-days: 30
8484

8585
- name: Upload screenshot reports
86-
uses: actions/upload-artifact@v4
86+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
8787
if: ${{ always() }}
8888
with:
8989
name: screenshot-reports
@@ -92,7 +92,7 @@ jobs:
9292
retention-days: 30
9393

9494
- name: Upload screenshot test results
95-
uses: actions/upload-artifact@v4
95+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
9696
if: ${{ always() }}
9797
with:
9898
name: screenshot-test-results

0 commit comments

Comments
 (0)