Skip to content

Commit d3fa16b

Browse files
authored
Pin all workflow actions to commit SHA1 hashes. (#558)
1 parent 8d8743d commit d3fa16b

4 files changed

Lines changed: 15 additions & 15 deletions

File tree

.github/workflows/create-release.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -15,10 +15,10 @@ jobs:
1515

1616
steps:
1717
- name: Checkout
18-
uses: actions/checkout@v6
18+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
1919

2020
- name: Set up Python
21-
uses: actions/setup-python@v6
21+
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6
2222
with:
2323
python-version: '3.x'
2424
cache: 'pip'
@@ -58,10 +58,10 @@ jobs:
5858
5959
- name: Extract release notes
6060
id: extract-release-notes
61-
uses: ffurrer2/extract-release-notes@v3
61+
uses: ffurrer2/extract-release-notes@273da39a24fb7db106a35526c8162815faffd31d # v3
6262

6363
- name: Create release
64-
uses: ncipollo/release-action@v1
64+
uses: ncipollo/release-action@339a81892b84b4eeb0f6e744e4574d79d0d9b8dd # v1
6565
with:
6666
body: ${{ steps.extract-release-notes.outputs.release_notes }}
6767
token: ${{ secrets.WORKFLOWS_CREATE_RELEASE_TOKEN }}
@@ -78,7 +78,7 @@ jobs:
7878
GH_TOKEN: ${{ secrets.WORKFLOWS_CREATE_RELEASE_TOKEN }}
7979

8080
- name: Publish on PyPI
81-
uses: pypa/gh-action-pypi-publish@release/v1
81+
uses: pypa/gh-action-pypi-publish@cef221092ed1bacb1cc03d23a2d87d1d172e277b # release/v1
8282
with:
8383
packages-dir: dist/
8484
# password: ${{ secrets.WORKFLOWS_PUBLISH_TO_PYPI_TOKEN }}

.github/workflows/pre-commit-autoupdate.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -15,12 +15,12 @@ jobs:
1515
auto-update:
1616
runs-on: ubuntu-latest
1717
steps:
18-
- uses: actions/checkout@v6
19-
- uses: actions/setup-python@v6
18+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
19+
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6
2020
with:
2121
python-version: '3.x'
22-
- uses: browniebroke/pre-commit-autoupdate-action@v1
23-
- uses: peter-evans/create-pull-request@v8
22+
- uses: browniebroke/pre-commit-autoupdate-action@f5c3ec85103b9f8f9be60b9c006cec763d2bdd02 # v1.0.1
23+
- uses: peter-evans/create-pull-request@c0f553fe549906ede9cf27b5156039d195d2ece0 # v8
2424
with:
2525
token: ${{ secrets.GITHUB_TOKEN }}
2626
branch: update/pre-commit-hooks

.github/workflows/scorecard.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -19,19 +19,19 @@ jobs:
1919

2020
steps:
2121
- name: Checkout
22-
uses: actions/checkout@v6
22+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
2323
with:
2424
persist-credentials: false
2525

2626
- name: Run Scorecard
27-
uses: ossf/scorecard-action@v2.4.3
27+
uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3
2828
with:
2929
results_file: scorecard-results.sarif
3030
results_format: sarif
3131
publish_results: true
3232

3333
- name: Upload results to GitHub Security tab
34-
uses: github/codeql-action/upload-sarif@v3
34+
uses: github/codeql-action/upload-sarif@5c8a8a642e79153f5d047b10ec1cba1d1cc65699 # v3
3535
with:
3636
sarif_file: scorecard-results.sarif
3737
category: scorecard

.github/workflows/test-package.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -23,10 +23,10 @@ jobs:
2323

2424
steps:
2525

26-
- uses: actions/checkout@v6
26+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
2727

2828
- name: Set up Python ${{ matrix.python-version }}
29-
uses: actions/setup-python@v6
29+
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6
3030
with:
3131
python-version: ${{ matrix.python-version }}
3232
cache: 'pip'
@@ -49,7 +49,7 @@ jobs:
4949
coverage xml -o ./coverage.xml
5050
5151
- name: Upload coverage to Codecov
52-
uses: codecov/codecov-action@v6
52+
uses: codecov/codecov-action@57e3a136b779b570ffcdbf80b3bdc90e7fab3de2 # v6
5353
with:
5454
token: ${{ secrets.CODECOV_TOKEN }}
5555
fail_ci_if_error: false

0 commit comments

Comments
 (0)