File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change 1010 permissions :
1111 contents : read
1212 steps :
13- - uses : actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1 .1
13+ - uses : actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0 .1
1414 - name : Enforce Guix primary / Nix fallback
1515 run : |
1616 # Check for package manager files
Original file line number Diff line number Diff line change @@ -19,12 +19,12 @@ jobs:
1919
2020 steps :
2121 - name : Checkout
22- uses : actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1 .1
22+ uses : actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0 .1
2323 with :
2424 fetch-depth : 0
2525
2626 - name : Setup SSH
27- uses : webfactory/ssh-agent@dc588b651fe13675774614f8e6a936a468676387 # v0.9.0
27+ uses : webfactory/ssh-agent@a6f90b1f127823b31d4d4a8d96047790581349bd # v0.9.1
2828 with :
2929 ssh-private-key : ${{ secrets.GITLAB_SSH_KEY }}
3030
@@ -49,12 +49,12 @@ jobs:
4949
5050 steps :
5151 - name : Checkout
52- uses : actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1 .1
52+ uses : actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0 .1
5353 with :
5454 fetch-depth : 0
5555
5656 - name : Setup SSH
57- uses : webfactory/ssh-agent@dc588b651fe13675774614f8e6a936a468676387 # v0.9.0
57+ uses : webfactory/ssh-agent@a6f90b1f127823b31d4d4a8d96047790581349bd # v0.9.1
5858 with :
5959 ssh-private-key : ${{ secrets.BITBUCKET_SSH_KEY }}
6060
Original file line number Diff line number Diff line change 1010 permissions :
1111 contents : read
1212 steps :
13- - uses : actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1 .1
13+ - uses : actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0 .1
1414 - name : Block npm/bun
1515 run : |
1616 if [ -f "package-lock.json" ] || [ -f "bun.lockb" ] || [ -f ".npmrc" ]; then
Original file line number Diff line number Diff line change 1010 permissions :
1111 contents : read
1212 steps :
13- - uses : actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1 .1
13+ - uses : actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0 .1
1414
1515 - name : Check file permissions
1616 run : |
4242 permissions :
4343 contents : read
4444 steps :
45- - uses : actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1 .1
45+ - uses : actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0 .1
4646 - name : Check documentation
4747 run : |
4848 MISSING=""
Original file line number Diff line number Diff line change @@ -16,17 +16,17 @@ jobs:
1616 id-token : write
1717 contents : read
1818 steps :
19- - uses : actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1 .1
19+ - uses : actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0 .1
2020 with :
2121 persist-credentials : false
2222
2323 - name : Run Scorecard
24- uses : ossf/scorecard-action@62b2cac7ed8198b15735ed49ab1e5cf35480ba46 # v2.4.0
24+ uses : ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3
2525 with :
2626 results_file : results.sarif
2727 results_format : sarif
2828
2929 - name : Upload results
30- uses : github/codeql-action/upload-sarif@662472033e021d55d94146f66f6058822b0b39fd # v3.28.1
30+ uses : github/codeql-action/upload-sarif@5d4e8d1aca955e8d8589aabd499c5cae939e33c7 # v3.28.1
3131 with :
3232 sarif_file : results.sarif
Original file line number Diff line number Diff line change 1010 permissions :
1111 contents : read
1212 steps :
13- - uses : actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1 .1
13+ - uses : actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0 .1
1414 - name : Security checks
1515 run : |
1616 FAILED=false
Original file line number Diff line number Diff line change 2222 permissions :
2323 contents : read
2424 steps :
25- - uses : actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1 .1
25+ - uses : actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0 .1
2626
2727 - name : RFC 9116 security.txt validation
2828 run : |
Original file line number Diff line number Diff line change 2222
2323 steps :
2424 - name : Checkout
25- uses : actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1 .1
25+ uses : actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0 .1
2626
2727 - name : Check SPDX Headers
2828 run : |
7272 echo "$unpinned"
7373 echo ""
7474 echo "Replace version tags with SHA pins, e.g.:"
75- echo " uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1"
75+ echo " uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v4.1.1"
7676 exit 1
7777 fi
7878 echo "All actions are SHA-pinned"
You can’t perform that action at this time.
0 commit comments