Skip to content

Commit 57a453d

Browse files
committed
アクションのバージョンをSHA指定に変更
1 parent b600a4a commit 57a453d

6 files changed

Lines changed: 26 additions & 24 deletions

File tree

.github/workflows/auto-merge.yml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,8 +12,6 @@ jobs:
1212
if: ${{ !github.event.pull_request.draft }}
1313
runs-on: ubuntu-latest
1414
steps:
15-
- uses: actions/checkout@v5
16-
1715
- name: Enable auto-merge for Pull Request
1816
run: |
1917
gh pr review --approve "$PR_URL"

.github/workflows/check-dist.yml

Lines changed: 9 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -13,23 +13,26 @@ jobs:
1313
runs-on: ubuntu-latest
1414

1515
steps:
16-
- uses: actions/checkout@v5
16+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
1717

18-
- name: Use Node.js 24.x
19-
uses: actions/setup-node@v5
18+
- name: Use Node.js
19+
uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
2020
with:
2121
node-version: 24.x
2222
check-latest: true
2323
package-manager-cache: false
2424

25-
- uses: pnpm/action-setup@v4
25+
- uses: pnpm/action-setup@a7487c7e89a18df4991f7f222e4898a00d66ddda # v4.1.0
2626
name: Install pnpm
2727
with:
2828
run_install: |
2929
- recursive: true
3030
args: [--no-frozen-lockfile, --strict-peer-dependencies]
3131
32-
- uses: oven-sh/setup-bun@v2
32+
- uses: oven-sh/setup-bun@735343b667d3e6f658f44d0eca948eb6282f2b76 # v2.0.2
33+
name: Install Bun
34+
with:
35+
bun-version: stable
3336

3437
- name: Rebuild the dist/ directory
3538
run: rm -rf dist && bun run --bun build && bun run --bun package
@@ -44,7 +47,7 @@ jobs:
4447
id: diff
4548

4649
# If index.js was different than expected, upload the expected version as an artifact
47-
- uses: actions/upload-artifact@v4
50+
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
4851
if: ${{ failure() && steps.diff.conclusion == 'failure' }}
4952
with:
5053
name: dist

.github/workflows/dependency-review.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -29,9 +29,9 @@ jobs:
2929
runs-on: ubuntu-latest
3030
steps:
3131
- name: 'Checkout repository'
32-
uses: actions/checkout@v5
32+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
3333
- name: 'Dependency Review'
34-
uses: actions/dependency-review-action@v4
34+
uses: actions/dependency-review-action@595b5aeba73380359d98a5e087f648dbb0edce1b # v4.7.3
3535
# Commonly enabled options, see https://github.com/actions/dependency-review-action#configuration-options for all available options.
3636
with:
3737
comment-summary-in-pr: always

.github/workflows/release-new-action-version.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,6 +20,6 @@ jobs:
2020
runs-on: ubuntu-latest
2121
steps:
2222
- name: Update the ${{ env.TAG_NAME }} tag
23-
uses: actions/publish-action@v0.4.0
23+
uses: actions/publish-action@23f4c6f12633a2da8f44938b71fde9afec138fb4 #v0.4.0
2424
with:
2525
source-tag: ${{ env.TAG_NAME }}

.github/workflows/scorecard.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -74,6 +74,6 @@ jobs:
7474
# Upload the results to GitHub's code scanning dashboard (optional).
7575
# Commenting out will disable upload of results to your repo's Code Scanning dashboard
7676
- name: "Upload to code-scanning"
77-
uses: github/codeql-action/upload-sarif@v3
77+
uses: github/codeql-action/upload-sarif@303c0aef88fc2fe5ff6d63d3b1596bfd83dfa1f9 # v3.30.4
7878
with:
7979
sarif_file: results.sarif

.github/workflows/test.yml

Lines changed: 13 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -21,35 +21,36 @@ jobs:
2121
AWS_REGION: us-west-2
2222
runs-on: ubuntu-latest
2323
steps:
24-
- uses: actions/checkout@v5
24+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
2525

2626
- name: Use Node.js
27-
uses: actions/setup-node@v5
27+
uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
2828
with:
2929
node-version: 'lts/*'
3030
check-latest: true
3131
package-manager-cache: pnpm
3232

33-
- uses: pnpm/action-setup@v4
33+
- uses: pnpm/action-setup@a7487c7e89a18df4991f7f222e4898a00d66ddda # v4.1.0
3434
name: Install pnpm
3535
with:
3636
run_install: |
3737
- recursive: true
3838
args: [--no-frozen-lockfile, --strict-peer-dependencies]
3939
40-
- uses: oven-sh/setup-bun@v2
40+
- uses: oven-sh/setup-bun@735343b667d3e6f658f44d0eca948eb6282f2b76 # v2.0.2
4141

4242
- name: build
4343
run: bun run --bun build && bun run --bun lint && bun run --bun package
4444

4545
- name: configure aws credentials
46-
uses: aws-actions/configure-aws-credentials@v5
46+
uses: aws-actions/configure-aws-credentials@a03048d87541d1d9fcf2ecf528a4a65ba9bd7838 # v5.0.0
4747
with:
4848
role-to-assume: ${{ secrets.AWS_OIDC_ROLE_ARN }}
4949
role-session-name: GitHubActions
5050
aws-region: ${{ env.AWS_REGION }}
5151

52-
- uses: actions/checkout@v5
52+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
53+
5354
- uses: ./
5455
id: stack-status
5556
with:
@@ -68,24 +69,24 @@ jobs:
6869
id: gen-timestamp
6970
run: echo "timestamp=$(date +%Y%m%d-%H%M%S)" >> $GITHUB_OUTPUT
7071

71-
- uses: actions/checkout@v5
72+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
7273

7374
- name: configure aws credentials
74-
uses: aws-actions/configure-aws-credentials@v5
75+
uses: aws-actions/configure-aws-credentials@a03048d87541d1d9fcf2ecf528a4a65ba9bd7838 # v5.0.0
7576
with:
7677
role-to-assume: ${{ secrets.AWS_OIDC_ROLE_ARN }}
7778
role-session-name: GitHubActions
7879
aws-region: ${{ env.AWS_REGION }}
7980

80-
- name: Use Node.js 24.x
81-
uses: actions/setup-node@v5
81+
- name: Use Node.js
82+
uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
8283
with:
8384
node-version: 24.x
8485
check-latest: true
8586
package-manager-cache: false
8687

87-
- uses: pnpm/action-setup@v4
88-
name: Install pnpm
88+
- name: Install pnpm
89+
uses: pnpm/action-setup@a7487c7e89a18df4991f7f222e4898a00d66ddda # v4.1.0
8990
with:
9091
run_install: |
9192
- recursive: true

0 commit comments

Comments
 (0)