Skip to content

Commit 7b7d930

Browse files
committed
chore: pin actions to sha
1 parent 58d1121 commit 7b7d930

File tree

13 files changed

+79
-79
lines changed

13 files changed

+79
-79
lines changed

.github/workflows/api-sync.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -16,9 +16,9 @@ jobs:
1616
name: Sync API Types
1717
runs-on: ubuntu-latest
1818
steps:
19-
- uses: actions/checkout@v6
19+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
2020

21-
- uses: actions/setup-go@v6
21+
- uses: actions/setup-go@4b73464bb391d4059bd26b0524d20df3927bd417 # v6.3.0
2222
with:
2323
go-version-file: go.mod
2424
cache: true
@@ -39,15 +39,15 @@ jobs:
3939
4040
- name: Generate token
4141
id: app-token
42-
uses: actions/create-github-app-token@v2
42+
uses: actions/create-github-app-token@fee1f7d63c2ff003460e3d139729b119787bc349 # v2.2.2
4343
with:
4444
app-id: ${{ secrets.APP_ID }}
4545
private-key: ${{ secrets.GH_APP_PRIVATE_KEY }}
4646

4747
- name: Create Pull Request
4848
if: steps.check.outputs.has_changes == 'true'
4949
id: cpr
50-
uses: peter-evans/create-pull-request@v8
50+
uses: peter-evans/create-pull-request@c0f553fe549906ede9cf27b5156039d195d2ece0 # v8.1.0
5151
with:
5252
token: ${{ steps.app-token.outputs.token }}
5353
commit-message: "chore: sync API types from infrastructure"

.github/workflows/automerge.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -18,14 +18,14 @@ jobs:
1818
# will not occur.
1919
- name: Dependabot metadata
2020
id: meta
21-
uses: dependabot/fetch-metadata@v2
21+
uses: dependabot/fetch-metadata@21025c705c08248db411dc16f3619e6b5f9ea21a # v2.5.0
2222
with:
2323
github-token: "${{ secrets.GITHUB_TOKEN }}"
2424

2525
- name: Generate token
2626
id: app-token
2727
if: ${{ steps.meta.outputs.update-type == null || steps.meta.outputs.update-type == 'version-update:semver-patch' || (!startsWith(steps.meta.outputs.previous-version, '0.') && steps.meta.outputs.update-type == 'version-update:semver-minor') }}
28-
uses: actions/create-github-app-token@v2
28+
uses: actions/create-github-app-token@fee1f7d63c2ff003460e3d139729b119787bc349 # v2.2.2
2929
with:
3030
app-id: ${{ secrets.APP_ID }}
3131
private-key: ${{ secrets.GH_APP_PRIVATE_KEY }}

.github/workflows/ci.yml

Lines changed: 15 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -14,21 +14,21 @@ jobs:
1414
name: Test
1515
runs-on: ubuntu-latest
1616
steps:
17-
- uses: actions/checkout@v6
17+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
1818

19-
- uses: actions/setup-go@v6
19+
- uses: actions/setup-go@4b73464bb391d4059bd26b0524d20df3927bd417 # v6.3.0
2020
with:
2121
go-version-file: go.mod
2222
cache: true
2323

2424
# Required by: internal/utils/credentials/keyring_test.go
25-
- uses: t1m0thyj/unlock-keyring@v1
25+
- uses: t1m0thyj/unlock-keyring@728cc718a07b5e7b62c269fc89295e248b24cba7 # v1.1.0
2626
- run: |
2727
pkgs=$(go list ./pkg/... | grep -Ev 'pkg/api' | paste -sd ',' -)
2828
go tool gotestsum -- -race -v -count=1 ./... \
2929
-coverpkg="./cmd/...,./internal/...,${pkgs}" -coverprofile=coverage.out
3030
31-
- uses: actions/upload-artifact@v7
31+
- uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
3232
with:
3333
name: code-coverage-report
3434
path: coverage.out
@@ -39,10 +39,10 @@ jobs:
3939
- test
4040
runs-on: ubuntu-latest
4141
steps:
42-
- uses: actions/download-artifact@v8
42+
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
4343
with:
4444
name: code-coverage-report
45-
- uses: coverallsapp/github-action@v2
45+
- uses: coverallsapp/github-action@5cbfd81b66ca5d10c19b062c04de0199c215fb6e # v2.3.7
4646
with:
4747
file: coverage.out
4848
format: golang
@@ -51,15 +51,15 @@ jobs:
5151
name: Lint
5252
runs-on: ubuntu-latest
5353
steps:
54-
- uses: actions/checkout@v6
54+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
5555

56-
- uses: actions/setup-go@v6
56+
- uses: actions/setup-go@4b73464bb391d4059bd26b0524d20df3927bd417 # v6.3.0
5757
with:
5858
go-version-file: go.mod
5959
# Linter requires no cache
6060
cache: false
6161

62-
- uses: golangci/golangci-lint-action@v9
62+
- uses: golangci/golangci-lint-action@1e7e51e771db61008b38414a730f564565cf7c20 # v9.2.0
6363
with:
6464
args: --timeout 3m --verbose
6565
version: latest
@@ -69,8 +69,8 @@ jobs:
6969
name: Start
7070
runs-on: ubuntu-latest
7171
steps:
72-
- uses: actions/checkout@v6
73-
- uses: actions/setup-go@v6
72+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
73+
- uses: actions/setup-go@4b73464bb391d4059bd26b0524d20df3927bd417 # v6.3.0
7474
with:
7575
go-version-file: go.mod
7676
cache: true
@@ -92,8 +92,8 @@ jobs:
9292
if: ${{ !github.event.pull_request.head.repo.fork }}
9393
runs-on: ubuntu-latest
9494
steps:
95-
- uses: actions/checkout@v6
96-
- uses: actions/setup-go@v6
95+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
96+
- uses: actions/setup-go@4b73464bb391d4059bd26b0524d20df3927bd417 # v6.3.0
9797
with:
9898
go-version-file: go.mod
9999
cache: true
@@ -107,9 +107,9 @@ jobs:
107107
name: Codegen
108108
runs-on: ubuntu-latest
109109
steps:
110-
- uses: actions/checkout@v6
110+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
111111

112-
- uses: actions/setup-go@v6
112+
- uses: actions/setup-go@4b73464bb391d4059bd26b0524d20df3927bd417 # v6.3.0
113113
with:
114114
go-version-file: go.mod
115115
cache: true

.github/workflows/codeql-analysis.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -56,11 +56,11 @@ jobs:
5656
# your codebase is analyzed, see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages
5757
steps:
5858
- name: Checkout repository
59-
uses: actions/checkout@v6
59+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
6060

6161
# Initializes the CodeQL tools for scanning.
6262
- name: Initialize CodeQL
63-
uses: github/codeql-action/init@v4
63+
uses: github/codeql-action/init@38697555549f1db7851b81482ff19f1fa5c4fedc # v4.34.1
6464
with:
6565
languages: ${{ matrix.language }}
6666
build-mode: ${{ matrix.build-mode }}
@@ -88,6 +88,6 @@ jobs:
8888
exit 1
8989
9090
- name: Perform CodeQL Analysis
91-
uses: github/codeql-action/analyze@v4
91+
uses: github/codeql-action/analyze@38697555549f1db7851b81482ff19f1fa5c4fedc # v4.34.1
9292
with:
9393
category: "/language:${{matrix.language}}"

.github/workflows/deploy.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,11 +14,11 @@ jobs:
1414
deploy:
1515
runs-on: ubuntu-latest
1616
steps:
17-
- uses: actions/checkout@v6
17+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
1818
with:
1919
fetch-depth: 0
2020
- id: app-token
21-
uses: actions/create-github-app-token@v2
21+
uses: actions/create-github-app-token@fee1f7d63c2ff003460e3d139729b119787bc349 # v2.2.2
2222
with:
2323
app-id: ${{ secrets.APP_ID }}
2424
private-key: ${{ secrets.GH_APP_PRIVATE_KEY }}

.github/workflows/install.yml

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -23,14 +23,14 @@ jobs:
2323
permissions:
2424
contents: read
2525
steps:
26-
- uses: actions/checkout@v6
26+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
2727

2828
- run: |
2929
jq -c '.version = "1.28.0"' package.json > tmp.$$.json
3030
mv tmp.$$.json package.json
3131
npm pack
3232
33-
- uses: actions/upload-artifact@v7
33+
- uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
3434
with:
3535
name: installer
3636
path: supabase-1.28.0.tgz
@@ -43,7 +43,7 @@ jobs:
4343
os: [ubuntu-latest, macos-latest, windows-latest]
4444
runs-on: ${{ matrix.os }}
4545
steps:
46-
- uses: actions/download-artifact@v8
46+
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
4747
with:
4848
name: installer
4949

@@ -59,7 +59,7 @@ jobs:
5959
os: [ubuntu-latest, macos-latest, windows-latest]
6060
runs-on: ${{ matrix.os }}
6161
steps:
62-
- uses: actions/download-artifact@v8
62+
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
6363
with:
6464
name: installer
6565

@@ -75,7 +75,7 @@ jobs:
7575
os: [ubuntu-latest, macos-latest, windows-latest]
7676
runs-on: ${{ matrix.os }}
7777
steps:
78-
- uses: actions/download-artifact@v8
78+
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
7979
with:
8080
name: installer
8181

@@ -98,7 +98,7 @@ jobs:
9898
os: [ubuntu-latest, macos-latest, windows-latest]
9999
runs-on: ${{ matrix.os }}
100100
steps:
101-
- uses: actions/download-artifact@v8
101+
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
102102
with:
103103
name: installer
104104

@@ -117,11 +117,11 @@ jobs:
117117
os: [ubuntu-latest, macos-latest]
118118
runs-on: ${{ matrix.os }}
119119
steps:
120-
- uses: actions/download-artifact@v8
120+
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
121121
with:
122122
name: installer
123123

124-
- uses: oven-sh/setup-bun@v2
124+
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
125125
with:
126126
bun-version: latest
127127
- run: |

.github/workflows/mirror-image.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -30,19 +30,19 @@ jobs:
3030
TAG=${{ github.event.client_payload.image || inputs.image }}
3131
echo "image=${TAG##*/}" >> $GITHUB_OUTPUT
3232
- name: configure aws credentials
33-
uses: aws-actions/configure-aws-credentials@v6.0.0
33+
uses: aws-actions/configure-aws-credentials@8df5847569e6427dd6c4fb1cf565c83acfa8afa7 # v6.0.0
3434
with:
3535
role-to-assume: ${{ secrets.PROD_AWS_ROLE }}
3636
aws-region: us-east-1
37-
- uses: docker/login-action@v4
37+
- uses: docker/login-action@b45d80f862d83dbcd57f89517bcf500b2ab88fb2 # v4.0.0
3838
with:
3939
registry: public.ecr.aws
40-
- uses: docker/login-action@v4
40+
- uses: docker/login-action@b45d80f862d83dbcd57f89517bcf500b2ab88fb2 # v4.0.0
4141
with:
4242
registry: ghcr.io
4343
username: ${{ github.actor }}
4444
password: ${{ secrets.GITHUB_TOKEN }}
45-
- uses: akhilerm/tag-push-action@v2.2.0
45+
- uses: akhilerm/tag-push-action@f35ff2cb99d407368b5c727adbcc14a2ed81d509 # v2.2.0
4646
with:
4747
src: docker.io/${{ github.event.client_payload.image || inputs.image }}
4848
dst: |

.github/workflows/mirror.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -26,8 +26,8 @@ jobs:
2626
tags: ${{ steps.list.outputs.tags }}
2727
curr: ${{ steps.curr.outputs.tags }}
2828
steps:
29-
- uses: actions/checkout@v6
30-
- uses: actions/setup-go@v6
29+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
30+
- uses: actions/setup-go@4b73464bb391d4059bd26b0524d20df3927bd417 # v6.3.0
3131
with:
3232
go-version-file: go.mod
3333
cache: true

.github/workflows/pg-prove.yml

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -12,8 +12,8 @@ jobs:
1212
outputs:
1313
image_tag: supabase/pg_prove:${{ steps.version.outputs.pg_prove }}
1414
steps:
15-
- uses: docker/setup-buildx-action@v4
16-
- uses: docker/build-push-action@v7
15+
- uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
16+
- uses: docker/build-push-action@d08e5c354a6adb9ed34480a06d141179aa583294 # v7.0.0
1717
with:
1818
load: true
1919
context: https://github.com/horrendo/pg_prove.git
@@ -43,15 +43,15 @@ jobs:
4343
image_digest: ${{ steps.build.outputs.digest }}
4444
steps:
4545
- run: docker context create builders
46-
- uses: docker/setup-buildx-action@v4
46+
- uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
4747
with:
4848
endpoint: builders
49-
- uses: docker/login-action@v4
49+
- uses: docker/login-action@b45d80f862d83dbcd57f89517bcf500b2ab88fb2 # v4.0.0
5050
with:
5151
username: ${{ secrets.DOCKER_USERNAME }}
5252
password: ${{ secrets.DOCKER_PASSWORD }}
5353
- id: build
54-
uses: docker/build-push-action@v7
54+
uses: docker/build-push-action@d08e5c354a6adb9ed34480a06d141179aa583294 # v7.0.0
5555
with:
5656
push: true
5757
context: https://github.com/horrendo/pg_prove.git
@@ -66,8 +66,8 @@ jobs:
6666
- build_image
6767
runs-on: ubuntu-latest
6868
steps:
69-
- uses: docker/setup-buildx-action@v4
70-
- uses: docker/login-action@v4
69+
- uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
70+
- uses: docker/login-action@b45d80f862d83dbcd57f89517bcf500b2ab88fb2 # v4.0.0
7171
with:
7272
username: ${{ secrets.DOCKER_USERNAME }}
7373
password: ${{ secrets.DOCKER_PASSWORD }}

.github/workflows/publish-migra.yml

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -12,8 +12,8 @@ jobs:
1212
outputs:
1313
image_tag: supabase/migra:${{ steps.version.outputs.migra }}
1414
steps:
15-
- uses: docker/setup-buildx-action@v4
16-
- uses: docker/build-push-action@v7
15+
- uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
16+
- uses: docker/build-push-action@d08e5c354a6adb9ed34480a06d141179aa583294 # v7.0.0
1717
with:
1818
load: true
1919
context: https://github.com/djrobstep/migra.git
@@ -43,15 +43,15 @@ jobs:
4343
image_digest: ${{ steps.build.outputs.digest }}
4444
steps:
4545
- run: docker context create builders
46-
- uses: docker/setup-buildx-action@v4
46+
- uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
4747
with:
4848
endpoint: builders
49-
- uses: docker/login-action@v4
49+
- uses: docker/login-action@b45d80f862d83dbcd57f89517bcf500b2ab88fb2 # v4.0.0
5050
with:
5151
username: ${{ secrets.DOCKER_USERNAME }}
5252
password: ${{ secrets.DOCKER_PASSWORD }}
5353
- id: build
54-
uses: docker/build-push-action@v7
54+
uses: docker/build-push-action@d08e5c354a6adb9ed34480a06d141179aa583294 # v7.0.0
5555
with:
5656
push: true
5757
context: https://github.com/djrobstep/migra.git
@@ -66,8 +66,8 @@ jobs:
6666
- build_image
6767
runs-on: ubuntu-latest
6868
steps:
69-
- uses: docker/setup-buildx-action@v4
70-
- uses: docker/login-action@v4
69+
- uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
70+
- uses: docker/login-action@b45d80f862d83dbcd57f89517bcf500b2ab88fb2 # v4.0.0
7171
with:
7272
username: ${{ secrets.DOCKER_USERNAME }}
7373
password: ${{ secrets.DOCKER_PASSWORD }}

0 commit comments

Comments
 (0)