diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index acf784e..021f080 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -79,7 +79,7 @@ jobs: python-version: "3.13" - name: Set up uv - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 + uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 with: enable-cache: true @@ -226,7 +226,7 @@ jobs: python-version: "3.13" - name: Set up uv - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 + uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 with: enable-cache: true diff --git a/.github/workflows/security-audit.yml b/.github/workflows/security-audit.yml index d1bafbf..bcd4cfc 100644 --- a/.github/workflows/security-audit.yml +++ b/.github/workflows/security-audit.yml @@ -59,7 +59,7 @@ jobs: retention-days: 30 - name: "Upload to code-scanning" - uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 + uses: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 with: sarif_file: results.sarif @@ -86,7 +86,7 @@ jobs: run: npm ci --ignore-scripts - name: Setup uv - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 + uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 with: python-version: "3.13" enable-cache: true @@ -148,7 +148,7 @@ jobs: fetch-depth: 0 - name: "Initialize CodeQL" - uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 + uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 with: languages: ${{ matrix.language }} packs: codeql/actions-queries @@ -160,4 +160,4 @@ jobs: npm run build --if-present - name: "Perform CodeQL Analysis" - uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 + uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 diff --git a/.github/workflows/test-and-build.yml b/.github/workflows/test-and-build.yml index 30351e0..fddb223 100644 --- a/.github/workflows/test-and-build.yml +++ b/.github/workflows/test-and-build.yml @@ -56,7 +56,7 @@ jobs: # maintainer re-runs), so gate on the token itself - name: Upload Node coverage and test results to Codecov if: env.CODECOV_TOKEN != '' - uses: codecov/codecov-action@0b35c9ecc4f0529d0eb674914510c22f85b196b4 # v7.1.0 + uses: codecov/codecov-action@303a32d7a59b442fa8d48b6a1cc6825c09c847a5 # v7.1.1 with: files: packages/node-commitlint/reports/lcov.info,packages/node-commitlint/reports/junit-vitest.xml flags: node @@ -141,7 +141,7 @@ jobs: python-version: ${{ matrix.python-version }} - name: Set up uv - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 + uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 with: enable-cache: true @@ -178,7 +178,7 @@ jobs: # maintainer re-runs), so gate on the token itself - name: Upload Python coverage and test results to Codecov if: env.CODECOV_TOKEN != '' - uses: codecov/codecov-action@0b35c9ecc4f0529d0eb674914510c22f85b196b4 # v7.1.0 + uses: codecov/codecov-action@303a32d7a59b442fa8d48b6a1cc6825c09c847a5 # v7.1.1 with: files: packages/python-gitlint/reports/coverage.xml,packages/python-gitlint/reports/junit-py.xml flags: python @@ -274,6 +274,6 @@ jobs: merge-multiple: true - name: SonarCloud Scan - uses: SonarSource/sonarqube-scan-action@22918119ff8e1ca75a623e15c8296b6ea4fbe28f # v8.2.1 + uses: SonarSource/sonarqube-scan-action@d209202bc7d53ff1cc128f7f907dac145c9d6ae9 # v8.3.0 env: SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}