Skip to content

Commit d3018ba

Browse files
authored
🔒 Pin GitHub Actions to commit SHAs (#161)
* 🔒 pin trufflehog.yml actions to commit SHAs * 🔒 pin doc-build.yml actions to commit SHAs * 🔒 pin doc-pr-build.yml actions to commit SHAs * 🔒 pin doc-pr-upload.yml actions to commit SHAs
1 parent 5838dda commit d3018ba

4 files changed

Lines changed: 5 additions & 5 deletions

File tree

.github/workflows/doc-build.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ on:
1414

1515
jobs:
1616
build:
17-
uses: huggingface/doc-builder/.github/workflows/build_main_documentation.yml@main
17+
uses: huggingface/doc-builder/.github/workflows/build_main_documentation.yml@90b4ee2c10b81b5c1a6367c4e6fc9e2fb510a7e3 # main
1818
with:
1919
commit_sha: ${{ github.sha }}
2020
package: Google-Cloud-Containers

.github/workflows/doc-pr-build.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ concurrency:
1515

1616
jobs:
1717
build:
18-
uses: huggingface/doc-builder/.github/workflows/build_pr_documentation.yml@main
18+
uses: huggingface/doc-builder/.github/workflows/build_pr_documentation.yml@90b4ee2c10b81b5c1a6367c4e6fc9e2fb510a7e3 # main
1919
with:
2020
commit_sha: ${{ github.event.pull_request.head.sha }}
2121
pr_number: ${{ github.event.number }}

.github/workflows/doc-pr-upload.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ on:
88

99
jobs:
1010
build:
11-
uses: huggingface/doc-builder/.github/workflows/upload_pr_documentation.yml@main
11+
uses: huggingface/doc-builder/.github/workflows/upload_pr_documentation.yml@90b4ee2c10b81b5c1a6367c4e6fc9e2fb510a7e3 # main
1212
with:
1313
package_name: google-cloud
1414
secrets:

.github/workflows/trufflehog.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,10 +8,10 @@ jobs:
88
runs-on: ubuntu-latest
99
steps:
1010
- name: Checkout code
11-
uses: actions/checkout@v4
11+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
1212
with:
1313
fetch-depth: 0
1414
- name: Secret Scanning
15-
uses: trufflesecurity/trufflehog@main
15+
uses: trufflesecurity/trufflehog@6bd2d14f7a4bc1e569fa3550efa7ec632a4fa67b # main
1616
with:
1717
extra_args: --results=verified,unknown --exclude-detectors=postgres

0 commit comments

Comments
 (0)