Skip to content

Commit 79caa49

Browse files
authored
Merge pull request #24504 from dvdksn/fix/pin-actions-sha-lock-deps
chore: pin Actions to commit SHA, lock npm versions, remove pull_request_target
2 parents 464a44a + 9919609 commit 79caa49

File tree

9 files changed

+44
-46
lines changed

9 files changed

+44
-46
lines changed

.github/workflows/agent-writer.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -13,16 +13,16 @@ jobs:
1313
runs-on: ubuntu-24.04
1414
steps:
1515
- name: Checkout
16-
uses: actions/checkout@v5
16+
uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5
1717

1818
- name: Set up Docker Buildx
19-
uses: docker/setup-buildx-action@v4
19+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4
2020

2121
- name: Install dependencies
2222
run: npm ci
2323

2424
- name: Run agent
25-
uses: docker/cagent-action@latest
25+
uses: docker/cagent-action@3a12dbd0c6cd7dda3d4e05f24f0143c9701456de # latest
2626
timeout-minutes: 15
2727
with:
2828
agent: ./tech_writer.yml

.github/workflows/build.yml

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -25,13 +25,13 @@ jobs:
2525
steps:
2626
-
2727
name: Set up Docker Buildx
28-
uses: docker/setup-buildx-action@v4
28+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4
2929
with:
3030
version: ${{ env.SETUP_BUILDX_VERSION }}
3131
driver-opts: image=${{ env.SETUP_BUILDKIT_IMAGE }}
3232
-
3333
name: Build
34-
uses: docker/bake-action@v7
34+
uses: docker/bake-action@82490499d2e5613fcead7e128237ef0b0ea210f7 # v7
3535
with:
3636
files: |
3737
docker-bake.hcl
@@ -44,21 +44,21 @@ jobs:
4444
steps:
4545
-
4646
name: Checkout
47-
uses: actions/checkout@v5
47+
uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5
4848
-
4949
name: Set up Docker Buildx
50-
uses: docker/setup-buildx-action@v4
50+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4
5151
-
5252
name: Build
53-
uses: docker/bake-action@v7
53+
uses: docker/bake-action@82490499d2e5613fcead7e128237ef0b0ea210f7 # v7
5454
with:
5555
source: .
5656
files: |
5757
docker-bake.hcl
5858
targets: release
5959
-
6060
name: Check Cloudfront config
61-
uses: docker/bake-action@v7
61+
uses: docker/bake-action@82490499d2e5613fcead7e128237ef0b0ea210f7 # v7
6262
with:
6363
source: .
6464
targets: aws-cloudfront-update
@@ -85,13 +85,13 @@ jobs:
8585
steps:
8686
-
8787
name: Checkout
88-
uses: actions/checkout@v5
88+
uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5
8989
-
9090
name: Set up Docker Buildx
91-
uses: docker/setup-buildx-action@v4
91+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4
9292
-
9393
name: Validate
94-
uses: docker/bake-action@v7
94+
uses: docker/bake-action@82490499d2e5613fcead7e128237ef0b0ea210f7 # v7
9595
with:
9696
source: .
9797
files: |

.github/workflows/deploy.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -30,12 +30,12 @@ jobs:
3030
steps:
3131
-
3232
name: Checkout
33-
uses: actions/checkout@v5
33+
uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5
3434
with:
3535
fetch-depth: 0
3636
-
3737
name: Set environment variables
38-
uses: actions/github-script@v8
38+
uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8
3939
env:
4040
INPUT_GITHUB-REF: ${{ github.ref }}
4141
with:
@@ -52,13 +52,13 @@ jobs:
5252
}
5353
-
5454
name: Set up Docker Buildx
55-
uses: docker/setup-buildx-action@v4
55+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4
5656
with:
5757
version: ${{ env.SETUP_BUILDX_VERSION }}
5858
driver-opts: image=${{ env.SETUP_BUILDKIT_IMAGE }}
5959
-
6060
name: Build website
61-
uses: docker/bake-action@v7
61+
uses: docker/bake-action@82490499d2e5613fcead7e128237ef0b0ea210f7 # v7
6262
with:
6363
source: .
6464
files: |
@@ -68,7 +68,7 @@ jobs:
6868
-
6969
name: Configure AWS Credentials
7070
if: ${{ env.DOCS_AWS_IAM_ROLE != '' }}
71-
uses: aws-actions/configure-aws-credentials@v5
71+
uses: aws-actions/configure-aws-credentials@61815dcd50bd041e203e49132bacad1fd04d2708 # v5
7272
with:
7373
role-to-assume: ${{ env.DOCS_AWS_IAM_ROLE }}
7474
aws-region: ${{ env.DOCS_AWS_REGION }}
@@ -106,7 +106,7 @@ jobs:
106106
-
107107
name: Update Cloudfront config
108108
if: ${{ env.DOCS_CLOUDFRONT_ID != '' }}
109-
uses: docker/bake-action@v7
109+
uses: docker/bake-action@82490499d2e5613fcead7e128237ef0b0ea210f7 # v7
110110
with:
111111
source: .
112112
files: |

.github/workflows/labeler.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ concurrency:
55
cancel-in-progress: true
66

77
on:
8-
pull_request_target:
8+
workflow_dispatch:
99

1010
jobs:
1111
labeler:

.github/workflows/nightly-docs-scan.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@ jobs:
2828

2929
steps:
3030
- name: Checkout repository
31-
uses: actions/checkout@v5
31+
uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5
3232
with:
3333
fetch-depth: 1
3434

@@ -55,7 +55,7 @@ jobs:
5555
private_key: ${{ secrets.CAGENT_REVIEWER_APP_PRIVATE_KEY }}
5656

5757
- name: Run documentation scan
58-
uses: docker/cagent-action@latest
58+
uses: docker/cagent-action@3a12dbd0c6cd7dda3d4e05f24f0143c9701456de # latest
5959
env:
6060
GH_TOKEN: ${{ steps.app-token.outputs.token || github.token }}
6161
with:

.github/workflows/pr-review.yml

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -5,8 +5,6 @@ on:
55
types: [created]
66
pull_request_review_comment:
77
types: [created]
8-
pull_request_target:
9-
types: [ready_for_review, opened]
108

119
permissions:
1210
contents: read
@@ -15,7 +13,7 @@ permissions:
1513

1614
jobs:
1715
review:
18-
uses: docker/cagent-action/.github/workflows/review-pr.yml@latest
16+
uses: docker/cagent-action/.github/workflows/review-pr.yml@3a12dbd0c6cd7dda3d4e05f24f0143c9701456de # latest
1917
secrets: inherit
2018
with:
2119
add-prompt-files: STYLE.md,COMPONENTS.md

.github/workflows/sync-cli-docs.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@ jobs:
2828
steps:
2929
-
3030
name: Checkout docs repo
31-
uses: actions/checkout@v5
31+
uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5
3232
with:
3333
fetch-depth: 0
3434
-
@@ -45,7 +45,7 @@ jobs:
4545
echo "Docker CLI version: **$VERSION**" | tee -a "$GITHUB_STEP_SUMMARY"
4646
-
4747
name: Checkout docker/cli repo
48-
uses: actions/checkout@v5
48+
uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5
4949
with:
5050
repository: docker/cli
5151
path: cli-source

.github/workflows/validate-upstream.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -34,12 +34,12 @@ jobs:
3434
steps:
3535
-
3636
name: Checkout
37-
uses: actions/checkout@v5
37+
uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5
3838
with:
3939
repository: docker/docs
4040
-
4141
name: Download data files
42-
uses: actions/download-artifact@v5
42+
uses: actions/download-artifact@634f93cb2916e3fdff6788551b99b062d0335ce0 # v5
4343
if: ${{ inputs.data-files-id != '' && inputs.data-files-folder != '' }}
4444
with:
4545
name: ${{ inputs.data-files-id }}
@@ -51,7 +51,7 @@ jobs:
5151
# that folder. If not, create a placeholder stub file for the data file.
5252
name: Copy data files
5353
if: ${{ inputs.data-files-id != '' && inputs.data-files-folder != '' }}
54-
uses: actions/github-script@v8
54+
uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8
5555
with:
5656
script: |
5757
const fs = require('fs');
@@ -84,13 +84,13 @@ jobs:
8484
}
8585
-
8686
name: Set up Docker Buildx
87-
uses: docker/setup-buildx-action@v4
87+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4
8888
with:
8989
version: ${{ env.SETUP_BUILDX_VERSION }}
9090
driver-opts: image=${{ env.SETUP_BUILDKIT_IMAGE }}
9191
-
9292
name: Validate
93-
uses: docker/bake-action@v7
93+
uses: docker/bake-action@82490499d2e5613fcead7e128237ef0b0ea210f7 # v7
9494
with:
9595
source: .
9696
files: |

package.json

Lines changed: 15 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -14,22 +14,22 @@
1414
},
1515
"homepage": "https://docs.docker.com/",
1616
"dependencies": {
17-
"@alpinejs/collapse": "^3.15.8",
18-
"@alpinejs/focus": "^3.15.8",
19-
"@alpinejs/persist": "^3.15.8",
20-
"@floating-ui/dom": "^1.7.6",
21-
"@material-symbols/svg-400": "^0.40.2",
22-
"@tailwindcss/cli": "^4.2.1",
23-
"@tailwindcss/typography": "^0.5.19",
24-
"alpinejs": "^3.15.8",
25-
"highlight.js": "^11.11.1",
26-
"marked": "^17.0.4",
27-
"tailwindcss": "^4.2.1"
17+
"@alpinejs/collapse": "3.15.8",
18+
"@alpinejs/focus": "3.15.8",
19+
"@alpinejs/persist": "3.15.8",
20+
"@floating-ui/dom": "1.7.6",
21+
"@material-symbols/svg-400": "0.40.2",
22+
"@tailwindcss/cli": "4.2.1",
23+
"@tailwindcss/typography": "0.5.19",
24+
"alpinejs": "3.15.8",
25+
"highlight.js": "11.11.1",
26+
"marked": "17.0.4",
27+
"tailwindcss": "4.2.1"
2828
},
2929
"devDependencies": {
30-
"markdownlint": "^0.40.0",
31-
"prettier": "^3.8.1",
32-
"prettier-plugin-go-template": "^0.0.15",
33-
"prettier-plugin-tailwindcss": "^0.7.2"
30+
"markdownlint": "0.40.0",
31+
"prettier": "3.8.1",
32+
"prettier-plugin-go-template": "0.0.15",
33+
"prettier-plugin-tailwindcss": "0.7.2"
3434
}
3535
}

0 commit comments

Comments
 (0)