diff --git a/.github/workflows/.builds.yml b/.github/workflows/.builds.yml index 1cc793c2..f923df96 100644 --- a/.github/workflows/.builds.yml +++ b/.github/workflows/.builds.yml @@ -25,7 +25,7 @@ jobs: package: [backend, migrations, frontend] timeout-minutes: 10 steps: - - uses: bcgov/action-builder-ghcr@1a3767a04ade69edf7e4857c44269d1100282581 # v4.1.0 + - uses: bcgov/action-builder-ghcr@1e4295b9766963ca36612b78560db6235120b80f # 4.1.1 with: package: ${{ matrix.package }} tags: ${{ inputs.tags }} diff --git a/.github/workflows/.deploy_stack.yml b/.github/workflows/.deploy_stack.yml index 5326882b..f6467300 100644 --- a/.github/workflows/.deploy_stack.yml +++ b/.github/workflows/.deploy_stack.yml @@ -50,7 +50,7 @@ jobs: package: [backend,migrations] steps: - name: Configure AWS Credentials - uses: aws-actions/configure-aws-credentials@e3dd6a429d7300a6a4c196c26e071d42e0343502 # v4 + uses: aws-actions/configure-aws-credentials@7474bc4690e29a8392af63c5b98e7449536d5c3a # v4 with: role-to-assume: ${{ secrets.AWS_DEPLOY_ROLE_ARN }} role-session-name: gha-ecr-push @@ -121,7 +121,7 @@ jobs: cache: 'npm' cache-dependency-path: frontend/package-lock.json - name: Configure AWS Credentials - uses: aws-actions/configure-aws-credentials@e3dd6a429d7300a6a4c196c26e071d42e0343502 # v4 + uses: aws-actions/configure-aws-credentials@7474bc4690e29a8392af63c5b98e7449536d5c3a # v4 with: role-to-assume: ${{ secrets.AWS_DEPLOY_ROLE_ARN }} aws-region: ${{ env.AWS_REGION }} diff --git a/.github/workflows/.deployer.yml b/.github/workflows/.deployer.yml index 25b29abb..30b02ffe 100644 --- a/.github/workflows/.deployer.yml +++ b/.github/workflows/.deployer.yml @@ -63,7 +63,7 @@ jobs: - name: Checkout uses: actions/checkout@v5 - name: Configure AWS Credentials - uses: aws-actions/configure-aws-credentials@e3dd6a429d7300a6a4c196c26e071d42e0343502 # v4 + uses: aws-actions/configure-aws-credentials@7474bc4690e29a8392af63c5b98e7449536d5c3a # v4 with: role-to-assume: ${{ secrets.AWS_DEPLOY_ROLE_ARN }} role-session-name: ${{ inputs.environment_name }}-deployment diff --git a/.github/workflows/.load-test.yml b/.github/workflows/.load-test.yml index 4af4aab8..4cd38785 100644 --- a/.github/workflows/.load-test.yml +++ b/.github/workflows/.load-test.yml @@ -25,7 +25,7 @@ jobs: steps: - uses: actions/checkout@v5 - uses: grafana/setup-k6-action@ffe7d7290dfa715e48c2ccc924d068444c94bde2 # v1 - - uses: grafana/run-k6-action@c6b79182b9b666aa4f630f4a6be9158ead62536e # v1 + - uses: grafana/run-k6-action@a15e2072ede004e8d46141e33d7f7dad8ad08d9d # v1 with: path: ./tests/load/${{ matrix.name }}-test.js flags: --vus 10 --duration 30s diff --git a/.github/workflows/.tests.yml b/.github/workflows/.tests.yml index e9cb8d25..e08ecbcc 100644 --- a/.github/workflows/.tests.yml +++ b/.github/workflows/.tests.yml @@ -29,7 +29,7 @@ jobs: ports: - 5432:5432 steps: - - uses: bcgov-nr/action-test-and-analyse@e2ba34132662c1638dbde806064eb7004b3761c3 # v1.3.0 + - uses: bcgov-nr/action-test-and-analyse@51b50be3bb2522e480ed8eab72735612deff7f15 # v1.4.0 env: SONAR_TOKEN: ${{ secrets.SONAR_TOKEN_BACKEND }} NODE_ENV: unittest @@ -55,7 +55,7 @@ jobs: runs-on: ubuntu-24.04 timeout-minutes: 5 steps: - - uses: bcgov/action-test-and-analyse@e2ba34132662c1638dbde806064eb7004b3761c3 # v1.3.0 + - uses: bcgov/action-test-and-analyse@51b50be3bb2522e480ed8eab72735612deff7f15 # v1.4.0 env: SONAR_TOKEN: ${{ secrets.SONAR_TOKEN_FRONTEND }} with: @@ -84,7 +84,7 @@ jobs: steps: - uses: actions/checkout@v5 - name: Run Trivy vulnerability scanner in repo mode - uses: aquasecurity/trivy-action@f9424c10c36e288d5fa79bd3dfd1aeb2d6eae808 # 0.33.0 + uses: aquasecurity/trivy-action@b6643a29fecd7f34b3597bc6acb0a98b03d33ff8 # 0.33.1 with: format: "sarif" output: "trivy-results.sarif" diff --git a/.github/workflows/pause-resources.yml b/.github/workflows/pause-resources.yml index 39cb0c33..1b4d6af0 100644 --- a/.github/workflows/pause-resources.yml +++ b/.github/workflows/pause-resources.yml @@ -41,7 +41,7 @@ jobs: - name: Checkout uses: actions/checkout@v5 - name: Configure AWS Credentials - uses: aws-actions/configure-aws-credentials@e3dd6a429d7300a6a4c196c26e071d42e0343502 # v4 + uses: aws-actions/configure-aws-credentials@7474bc4690e29a8392af63c5b98e7449536d5c3a # v4 with: role-to-assume: ${{ secrets.AWS_DEPLOY_ROLE_ARN }} role-session-name: gha-pause-resources @@ -61,7 +61,7 @@ jobs: - name: Checkout uses: actions/checkout@v5 - name: Configure AWS Credentials - uses: aws-actions/configure-aws-credentials@e3dd6a429d7300a6a4c196c26e071d42e0343502 # v4 + uses: aws-actions/configure-aws-credentials@7474bc4690e29a8392af63c5b98e7449536d5c3a # v4 with: role-to-assume: ${{ secrets.AWS_DEPLOY_ROLE_ARN }} role-session-name: gha-pause-resources diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index f8c08d51..0f1660d7 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -29,7 +29,7 @@ jobs: - uses: actions/checkout@v5 - name: Conventional Changelog Update if: (github.event_name != 'release') - uses: TriPSs/conventional-changelog-action@67139193614f5b9e8db87da1bd4240922b34d765 # v6 + uses: TriPSs/conventional-changelog-action@5f00b899ccbbcbc112bd6d715d5e76e7a9e4501d # v6 id: changelog continue-on-error: true with: @@ -115,7 +115,7 @@ jobs: if: (needs.vars.outputs.tag != '' && github.event_name != 'release') steps: - name: Create Release - uses: softprops/action-gh-release@72f2c25fcb47643c292f7107632f7a47c1df5cd8 # v2 + uses: softprops/action-gh-release@6da8fa9354ddfdc4aeace5fc48d7f679b5214090 # v2 if: ${{ needs.vars.outputs.tag != ''}} continue-on-error: true env: diff --git a/.github/workflows/resume-resources.yml b/.github/workflows/resume-resources.yml index 57469edd..b04b1385 100644 --- a/.github/workflows/resume-resources.yml +++ b/.github/workflows/resume-resources.yml @@ -41,7 +41,7 @@ jobs: - name: Checkout uses: actions/checkout@v5 - name: Configure AWS Credentials - uses: aws-actions/configure-aws-credentials@e3dd6a429d7300a6a4c196c26e071d42e0343502 # v4 + uses: aws-actions/configure-aws-credentials@7474bc4690e29a8392af63c5b98e7449536d5c3a # v4 with: role-to-assume: ${{ secrets.AWS_DEPLOY_ROLE_ARN }} role-session-name: gha-resume-resources @@ -61,7 +61,7 @@ jobs: - name: Checkout uses: actions/checkout@v5 - name: Configure AWS Credentials - uses: aws-actions/configure-aws-credentials@e3dd6a429d7300a6a4c196c26e071d42e0343502 # v4 + uses: aws-actions/configure-aws-credentials@7474bc4690e29a8392af63c5b98e7449536d5c3a # v4 with: role-to-assume: ${{ secrets.AWS_DEPLOY_ROLE_ARN }} role-session-name: gha-resume-resources