Skip to content

Commit aa24e5b

Browse files
chore(deps): pin dependencies (#966)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
1 parent 5226959 commit aa24e5b

File tree

6 files changed

+27
-27
lines changed

6 files changed

+27
-27
lines changed

.github/workflows/ci.yml

Lines changed: 13 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -15,13 +15,13 @@ jobs:
1515
permissions:
1616
contents: read
1717
steps:
18-
- uses: actions/checkout@v5
19-
- uses: oven-sh/setup-bun@v2
18+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
19+
- uses: oven-sh/setup-bun@735343b667d3e6f658f44d0eca948eb6282f2b76 # v2
2020
with:
2121
bun-version: latest
2222
- run: bun install --frozen-lockfile
2323
- run: bun run build
24-
- uses: actions/upload-artifact@v4
24+
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
2525
with:
2626
name: build
2727
path: packages/*/dist/**
@@ -37,12 +37,12 @@ jobs:
3737
permissions:
3838
contents: read
3939
steps:
40-
- uses: actions/checkout@v5
41-
- uses: actions/download-artifact@v4
40+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
41+
- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
4242
with:
4343
name: build
4444
path: packages
45-
- uses: oven-sh/setup-bun@v2
45+
- uses: oven-sh/setup-bun@735343b667d3e6f658f44d0eca948eb6282f2b76 # v2
4646
with:
4747
bun-version: latest
4848
- run: bun install --frozen-lockfile
@@ -77,15 +77,15 @@ jobs:
7777
permissions:
7878
contents: read
7979
steps:
80-
- uses: actions/checkout@v5
81-
- uses: actions/download-artifact@v4
80+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
81+
- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
8282
with:
8383
name: build
8484
path: packages
85-
- uses: actions/setup-node@v4
85+
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
8686
with:
8787
node-version: ${{ matrix.node-version }}
88-
- uses: oven-sh/setup-bun@v2
88+
- uses: oven-sh/setup-bun@735343b667d3e6f658f44d0eca948eb6282f2b76 # v2
8989
with:
9090
bun-version: latest
9191
- run: bun install --frozen-lockfile
@@ -106,12 +106,12 @@ jobs:
106106
permissions:
107107
contents: read
108108
steps:
109-
- uses: actions/checkout@v5
110-
- uses: actions/download-artifact@v4
109+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
110+
- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
111111
with:
112112
name: build
113113
path: packages
114-
- uses: oven-sh/setup-bun@v2
114+
- uses: oven-sh/setup-bun@735343b667d3e6f658f44d0eca948eb6282f2b76 # v2
115115
with:
116116
bun-version: latest
117117
- run: bun install --frozen-lockfile

.github/workflows/codeql.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -27,11 +27,11 @@ jobs:
2727
- language: javascript-typescript
2828
build-mode: none
2929
steps:
30-
- uses: actions/checkout@v5
31-
- uses: github/codeql-action/init@v3
30+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
31+
- uses: github/codeql-action/init@df559355d593797519d70b90fc8edd5db049e7a2 # v3
3232
with:
3333
languages: ${{ matrix.language }}
3434
build-mode: ${{ matrix.build-mode }}
3535
queries: security-and-quality
36-
- uses: github/codeql-action/autobuild@v3
37-
- uses: github/codeql-action/analyze@v3
36+
- uses: github/codeql-action/autobuild@df559355d593797519d70b90fc8edd5db049e7a2 # v3
37+
- uses: github/codeql-action/analyze@df559355d593797519d70b90fc8edd5db049e7a2 # v3

.github/workflows/semgrep-pro.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -14,17 +14,17 @@ jobs:
1414
runs-on: ubuntu-latest
1515
timeout-minutes: 10
1616
container:
17-
image: semgrep/semgrep
17+
image: semgrep/semgrep@sha256:6bd07d7b166b097e1384f41b94a62d8c8a26a4fff8713992c296e053310da01f
1818
permissions:
1919
actions: read
2020
contents: read
2121
security-events: write
2222
steps:
23-
- uses: actions/checkout@v5
23+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
2424
- run: semgrep ci --sarif-output=semgrep.sarif
2525
env:
2626
SEMGREP_APP_TOKEN: ${{ secrets.SEMGREP_APP_TOKEN }}
27-
- uses: github/codeql-action/upload-sarif@v3
27+
- uses: github/codeql-action/upload-sarif@df559355d593797519d70b90fc8edd5db049e7a2 # v3
2828
if: always()
2929
with:
3030
sarif_file: semgrep.sarif

.github/workflows/semgrep.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -14,17 +14,17 @@ jobs:
1414
runs-on: ubuntu-latest
1515
timeout-minutes: 5
1616
container:
17-
image: semgrep/semgrep
17+
image: semgrep/semgrep@sha256:6bd07d7b166b097e1384f41b94a62d8c8a26a4fff8713992c296e053310da01f
1818
permissions:
1919
actions: read
2020
contents: read
2121
security-events: write
2222
steps:
23-
- uses: actions/checkout@v5
23+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
2424
- run: semgrep ci --sarif-output=semgrep.sarif
2525
env:
2626
SEMGREP_RULES: p/default p/owasp-top-ten p/cwe-top-25 p/gitleaks p/r2c-security-audit
27-
- uses: github/codeql-action/upload-sarif@v3
27+
- uses: github/codeql-action/upload-sarif@df559355d593797519d70b90fc8edd5db049e7a2 # v3
2828
if: always()
2929
with:
3030
sarif_file: semgrep.sarif

.github/workflows/sherif.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,8 +14,8 @@ jobs:
1414
permissions:
1515
contents: read
1616
steps:
17-
- uses: actions/checkout@v5
18-
- uses: oven-sh/setup-bun@v2
17+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
18+
- uses: oven-sh/setup-bun@735343b667d3e6f658f44d0eca948eb6282f2b76 # v2
1919
with:
2020
bun-version: latest
2121
- run: bunx sherif@latest

.github/workflows/typos.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,5 +14,5 @@ jobs:
1414
permissions:
1515
contents: read
1616
steps:
17-
- uses: actions/checkout@v5
18-
- uses: crate-ci/typos@v1
17+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
18+
- uses: crate-ci/typos@a67079b4ae32e18c3f53d75368c52ce53b5fb56b # v1

0 commit comments

Comments
 (0)