Skip to content

Commit db16a98

Browse files
authored
chore: dependabot (#170)
1 parent 42de954 commit db16a98

File tree

4 files changed

+23
-21
lines changed

4 files changed

+23
-21
lines changed

.github/dependabot.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,3 +4,5 @@ updates:
44
directory: "/"
55
schedule:
66
interval: "weekly"
7+
cooldown:
8+
default-days: 7

.github/workflows/contracts.yml

Lines changed: 15 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -29,21 +29,21 @@ jobs:
2929

3030
steps:
3131
- name: Checkout sources
32-
uses: actions/checkout@v5
32+
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
3333
with:
3434
submodules: recursive
3535
persist-credentials: false
3636

3737
- name: Install Foundry
38-
uses: foundry-rs/foundry-toolchain@50d5a8956f2e319df19e6b57539d7e2acb9f8c1e # v1.5.0
38+
uses: foundry-rs/foundry-toolchain@8b0419c685ef46cb79ec93fbdc131174afceb730 # v1.6.0
3939
with:
4040
version: nightly
4141

4242
- name: Setup LCOV
4343
uses: hrishikesh-kadam/setup-lcov@6c1aa0cc9e1c02f9f58f01ac599f1064ccc83470 # v1
4444

4545
- name: Install Node.js 18
46-
uses: actions/setup-node@v6
46+
uses: actions/setup-node@395ad3262231945c25e8478fd5baf05154b1d79f # v6.1.0
4747
with:
4848
node-version: '18'
4949

@@ -52,7 +52,7 @@ jobs:
5252
run: echo "::set-output name=dir::$(yarn cache dir)"
5353

5454
- name: Cache yarn dependencies
55-
uses: actions/cache@v4
55+
uses: actions/cache@9255dc7a253b0ccc959486e2bca901246202afeb # v5.0.1
5656
id: yarn-cache # use this to check for `cache-hit` (`steps.yarn-cache.outputs.cache-hit != 'true'`)
5757
with:
5858
path: ${{ steps.yarn-cache-dir-path.outputs.dir }}
@@ -62,7 +62,7 @@ jobs:
6262
6363
- name: Cache node_modules
6464
id: npm_cache
65-
uses: actions/cache@v4
65+
uses: actions/cache@9255dc7a253b0ccc959486e2bca901246202afeb # v5.0.1
6666
with:
6767
path: node_modules
6868
key: node_modules-${{ hashFiles('yarn.lock') }}
@@ -84,7 +84,7 @@ jobs:
8484
run : lcov --rc branch_coverage=1 --remove ./lcov.info -o ./lcov.info.pruned 'src/mocks/*' 'src/test/*' 'scripts/*' 'node_modules/*' 'lib/*' --ignore-errors unused,unused
8585

8686
- name: Upload coverage reports to Codecov
87-
uses: codecov/codecov-action@5a1091511ad55cbe89839c7260b706298ca349f7 # v5.5.1
87+
uses: codecov/codecov-action@671740ac38dd9b0130fbe1cec585b89eea48d3de # v5.5.2
8888
env:
8989
CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }}
9090
with:
@@ -98,13 +98,13 @@ jobs:
9898

9999
steps:
100100
- name: Checkout sources
101-
uses: actions/checkout@v5
101+
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
102102
with:
103103
submodules: recursive
104104
persist-credentials: false
105105

106106
- name: Install Node.js 18
107-
uses: actions/setup-node@v6
107+
uses: actions/setup-node@395ad3262231945c25e8478fd5baf05154b1d79f # v6.1.0
108108
with:
109109
node-version: '18'
110110

@@ -113,7 +113,7 @@ jobs:
113113
run: echo "::set-output name=dir::$(yarn cache dir)"
114114

115115
- name: Cache yarn dependencies
116-
uses: actions/cache@v4
116+
uses: actions/cache@9255dc7a253b0ccc959486e2bca901246202afeb # v5.0.1
117117
id: yarn-cache # use this to check for `cache-hit` (`steps.yarn-cache.outputs.cache-hit != 'true'`)
118118
with:
119119
path: ${{ steps.yarn-cache-dir-path.outputs.dir }}
@@ -123,7 +123,7 @@ jobs:
123123
124124
- name: Cache node_modules
125125
id: npm_cache
126-
uses: actions/cache@v4
126+
uses: actions/cache@9255dc7a253b0ccc959486e2bca901246202afeb # v5.0.1
127127
with:
128128
path: node_modules
129129
key: node_modules-${{ hashFiles('yarn.lock') }}
@@ -147,25 +147,25 @@ jobs:
147147
security-events: write
148148

149149
steps:
150-
- uses: actions/checkout@v5
150+
- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
151151
with:
152152
submodules: recursive
153153
persist-credentials: false
154154

155-
- uses: actions/setup-node@v6
155+
- uses: actions/setup-node@395ad3262231945c25e8478fd5baf05154b1d79f # v6.1.0
156156
with:
157157
node-version: '18'
158158

159159
- run: yarn install --frozen-lockfile
160160

161-
- uses: foundry-rs/foundry-toolchain@50d5a8956f2e319df19e6b57539d7e2acb9f8c1e # v1.5.0
161+
- uses: foundry-rs/foundry-toolchain@8b0419c685ef46cb79ec93fbdc131174afceb730 # v1.6.0
162162
with:
163163
version: nightly
164164

165165
- name: Build contracts
166166
run: forge build --build-info --out out --evm-version cancun
167167

168-
- uses: actions/setup-python@v6
168+
- uses: actions/setup-python@83679a892e2d95755f2dac6acb0bfd1e9ac5d548 # v6.1.0
169169
with:
170170
python-version: '3.11'
171171

@@ -186,7 +186,7 @@ jobs:
186186
--json slither-report.json \
187187
--markdown-root slither-report.md
188188
189-
- uses: actions/upload-artifact@v5
189+
- uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6.0.0
190190
with:
191191
name: slither-static-analysis
192192
path: |

.github/workflows/docker-release.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ jobs:
1212

1313
steps:
1414
- name: Check out repository
15-
uses: actions/checkout@v5
15+
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
1616
with:
1717
submodules: true
1818
persist-credentials: false
@@ -21,10 +21,10 @@ jobs:
2121
run: git submodule update --init --recursive
2222

2323
- name: Set up QEMU
24-
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3.6.0
24+
uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130 # v3.7.0
2525

2626
- name: Setup Node.js environment
27-
uses: actions/setup-node@v6
27+
uses: actions/setup-node@395ad3262231945c25e8478fd5baf05154b1d79f # v6.1.0
2828
with:
2929
node-version: '21'
3030
package-manager-cache: false
@@ -33,7 +33,7 @@ jobs:
3333
run: npm install
3434

3535
- name: Set up Docker Buildx
36-
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
36+
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0
3737
with:
3838
cache-binary: false
3939

.github/workflows/zizmor.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -18,12 +18,12 @@ jobs:
1818

1919
steps:
2020
- name: Checkout repository
21-
uses: actions/checkout@v5
21+
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
2222
with:
2323
persist-credentials: false
2424

2525
- name: Install the latest version of uv
26-
uses: astral-sh/setup-uv@85856786d1ce8acfbcc2f13a5f3fbd6b938f9f41 # v7.1.2
26+
uses: astral-sh/setup-uv@681c641aba71e4a1c380be3ab5e12ad51f415867 # v7.1.6
2727

2828
- name: Run zizmor
2929
run: uvx zizmor --format sarif . > results.sarif

0 commit comments

Comments
 (0)