Skip to content

Commit ab05779

Browse files
authored
chore: pin GitHub Actions (#777)
1 parent 9b92dd8 commit ab05779

File tree

7 files changed

+44
-44
lines changed

7 files changed

+44
-44
lines changed

.github/workflows/GHPages.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -24,9 +24,9 @@ jobs:
2424
runs-on: ubuntu-latest
2525
steps:
2626
- name: Checkout
27-
uses: actions/checkout@v5
28-
- uses: pnpm/action-setup@v4
29-
- uses: actions/setup-node@v6
27+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
28+
- uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061 # v4.2.0
29+
- uses: actions/setup-node@2028fbc5c25fe9cf00d9f06a71cc4710d4507903 # v6.0.0
3030
- name: Install And Build
3131
run: |+
3232
pnpm install --frozen-lockfile
@@ -36,11 +36,11 @@ jobs:
3636
pnpm run pre-build
3737
pnpm run build
3838
- name: Setup Pages
39-
uses: actions/configure-pages@v5
39+
uses: actions/configure-pages@983d7736d9b0ae728b81ab479565c72886d7745b # v5.0.0
4040
- name: Upload artifact
41-
uses: actions/upload-pages-artifact@v4
41+
uses: actions/upload-pages-artifact@7b1f4a764d45c48632c6b24a0339c27f5614fb0b # v4.0.0
4242
with:
4343
path: ./explorer-v2/build
4444
- name: Deploy to GitHub Pages
4545
id: deployment
46-
uses: actions/deploy-pages@v4
46+
uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e # v4.0.5

.github/workflows/NodeCI.yml

Lines changed: 22 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -10,9 +10,9 @@ jobs:
1010
lint:
1111
runs-on: ubuntu-latest
1212
steps:
13-
- uses: actions/checkout@v5
14-
- uses: pnpm/action-setup@v4
15-
- uses: actions/setup-node@v6
13+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
14+
- uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061 # v4.2.0
15+
- uses: actions/setup-node@2028fbc5c25fe9cf00d9f06a71cc4710d4507903 # v6.0.0
1616
- name: Install Packages
1717
run: pnpm install --frozen-lockfile
1818
- name: Lint
@@ -25,10 +25,10 @@ jobs:
2525
matrix:
2626
node-version: [18.x, 20.x, 22.x, latest]
2727
steps:
28-
- uses: actions/checkout@v5
29-
- uses: pnpm/action-setup@v4
28+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
29+
- uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061 # v4.2.0
3030
- name: Use Node.js ${{ matrix.node-version }}
31-
uses: actions/setup-node@v6
31+
uses: actions/setup-node@2028fbc5c25fe9cf00d9f06a71cc4710d4507903 # v6.0.0
3232
with:
3333
node-version: ${{ matrix.node-version }}
3434
- name: Install Packages
@@ -38,10 +38,10 @@ jobs:
3838
test-for-svelte-v5:
3939
runs-on: ubuntu-latest
4040
steps:
41-
- uses: actions/checkout@v5
42-
- uses: pnpm/action-setup@v4
41+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
42+
- uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061 # v4.2.0
4343
- name: Use Node.js
44-
uses: actions/setup-node@v6
44+
uses: actions/setup-node@2028fbc5c25fe9cf00d9f06a71cc4710d4507903 # v6.0.0
4545
- name: Install Packages
4646
run: pnpm install --frozen-lockfile
4747
- name: Test
@@ -50,10 +50,10 @@ jobs:
5050
test-for-svelte-v4:
5151
runs-on: ubuntu-latest
5252
steps:
53-
- uses: actions/checkout@v5
54-
- uses: pnpm/action-setup@v4
53+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
54+
- uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061 # v4.2.0
5555
- name: Use Node.js
56-
uses: actions/setup-node@v6
56+
uses: actions/setup-node@2028fbc5c25fe9cf00d9f06a71cc4710d4507903 # v6.0.0
5757
- name: Install Svelte v4
5858
run: |+
5959
pnpm install -D svelte@4
@@ -69,10 +69,10 @@ jobs:
6969
matrix:
7070
node-version: [18.x]
7171
steps:
72-
- uses: actions/checkout@v5
73-
- uses: pnpm/action-setup@v4
72+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
73+
- uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061 # v4.2.0
7474
- name: Use Node.js ${{ matrix.node-version }}
75-
uses: actions/setup-node@v6
75+
uses: actions/setup-node@2028fbc5c25fe9cf00d9f06a71cc4710d4507903 # v6.0.0
7676
with:
7777
node-version: ${{ matrix.node-version }}
7878
- name: Install Svelte v3
@@ -86,9 +86,9 @@ jobs:
8686
update-fixtures:
8787
runs-on: ubuntu-latest
8888
steps:
89-
- uses: actions/checkout@v5
90-
- uses: pnpm/action-setup@v4
91-
- uses: actions/setup-node@v6
89+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
90+
- uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061 # v4.2.0
91+
- uses: actions/setup-node@2028fbc5c25fe9cf00d9f06a71cc4710d4507903 # v6.0.0
9292
- name: Install Packages
9393
run: pnpm install --frozen-lockfile
9494
- name: Update fixtures
@@ -100,14 +100,14 @@ jobs:
100100
test-and-coverage:
101101
runs-on: ubuntu-latest
102102
steps:
103-
- uses: actions/checkout@v5
104-
- uses: pnpm/action-setup@v4
105-
- uses: actions/setup-node@v6
103+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
104+
- uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061 # v4.2.0
105+
- uses: actions/setup-node@2028fbc5c25fe9cf00d9f06a71cc4710d4507903 # v6.0.0
106106
- name: Install Packages
107107
run: pnpm install --frozen-lockfile
108108
- name: Test
109109
run: pnpm run cover
110110
- name: Coveralls GitHub Action
111-
uses: coverallsapp/github-action@v2
111+
uses: coverallsapp/github-action@648a8eb78e6d50909eff900e4ec85cab4524a45b # v2.3.6
112112
with:
113113
github-token: ${{ secrets.GITHUB_TOKEN }}

.github/workflows/Release.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -18,24 +18,24 @@ jobs:
1818
runs-on: ubuntu-latest
1919
steps:
2020
- name: Checkout Repo
21-
uses: actions/checkout@v5
21+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
2222
with:
2323
# This makes Actions fetch all Git history so that Changesets can generate changelogs with the correct commits
2424
fetch-depth: 0
2525

2626
- name: Setup pnpm
27-
uses: pnpm/action-setup@v4
27+
uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061 # v4.2.0
2828

2929
- name: Setup Node.js
30-
uses: actions/setup-node@v6
30+
uses: actions/setup-node@2028fbc5c25fe9cf00d9f06a71cc4710d4507903 # v6.0.0
3131
with:
3232
node-version: 24
3333
- name: Install Dependencies
3434
run: pnpm install --frozen-lockfile
3535

3636
- name: Create Release Pull Request or Publish to npm
3737
id: changesets
38-
uses: changesets/action@v1
38+
uses: changesets/action@e0145edc7d9d8679003495b11f87bd8ef63c0cba # v1.5.3
3939
with:
4040
# this expects you to have a npm script called version that runs some logic and then calls `changeset version`.
4141
version: pnpm run version:ci

.github/workflows/format.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -10,9 +10,9 @@ jobs:
1010
format:
1111
runs-on: ubuntu-latest
1212
steps:
13-
- uses: actions/checkout@v5
14-
- uses: pnpm/action-setup@v4
15-
- uses: actions/setup-node@v6
13+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
14+
- uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061 # v4.2.0
15+
- uses: actions/setup-node@2028fbc5c25fe9cf00d9f06a71cc4710d4507903 # v6.0.0
1616
- name: Install Packages
1717
run: pnpm install --frozen-lockfile
1818
- name: Format

.github/workflows/pkg.pr.new-comment.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -16,16 +16,16 @@ jobs:
1616
name: Update comment
1717
runs-on: ubuntu-latest
1818
steps:
19-
- uses: actions/checkout@v5
19+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
2020
- name: Download artifact
21-
uses: actions/download-artifact@v5
21+
uses: actions/download-artifact@634f93cb2916e3fdff6788551b99b062d0335ce0 # v5.0.0
2222
with:
2323
name: output
2424
github-token: ${{ secrets.GITHUB_TOKEN }}
2525
run-id: ${{ github.event.workflow_run.id }}
2626
- run: ls -R .
2727
- name: Post or update comment
28-
uses: actions/github-script@v8
28+
uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0
2929
with:
3030
github-token: ${{ secrets.GITHUB_TOKEN }}
3131
script: |

.github/workflows/pkg.pr.new.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -12,16 +12,16 @@ jobs:
1212
runs-on: ubuntu-latest
1313

1414
steps:
15-
- uses: actions/checkout@v5
16-
- uses: pnpm/action-setup@v4
17-
- uses: actions/setup-node@v6
15+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
16+
- uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061 # v4.2.0
17+
- uses: actions/setup-node@2028fbc5c25fe9cf00d9f06a71cc4710d4507903 # v6.0.0
1818
- name: Install Packages
1919
run: pnpm install --frozen-lockfile
2020
- name: Build
2121
run: pnpm run build
2222
- run: pnpx pkg-pr-new publish --compact --json output.json --comment=off
2323
- name: Add metadata to output
24-
uses: actions/github-script@v8
24+
uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0
2525
with:
2626
github-token: ${{ secrets.GITHUB_TOKEN }}
2727
script: |
@@ -35,7 +35,7 @@ jobs:
3535
: context.payload.after;
3636
fs.writeFileSync('output.json', JSON.stringify(output), 'utf8');
3737
- name: Upload output
38-
uses: actions/upload-artifact@v4
38+
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
3939
with:
4040
name: output
4141
path: ./output.json

.github/workflows/stale.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ jobs:
1313
name: Close stale issues with missing information
1414
runs-on: ubuntu-latest
1515
steps:
16-
- uses: actions/stale@v10
16+
- uses: actions/stale@5f858e3efba33a5ca4407a664cc011ad407f2008 # v10.1.0
1717
with:
1818
any-of-labels: "needs repro,needs info,needs more info"
1919
days-before-stale: 60

0 commit comments

Comments
 (0)