Skip to content

Commit 9a2f9c4

Browse files
[StepSecurity] ci: Harden GitHub Actions (#1426)
Co-authored-by: nils måsén <[email protected]>
1 parent 0a0998f commit 9a2f9c4

File tree

3 files changed

+8
-8
lines changed

3 files changed

+8
-8
lines changed

.github/workflows/pull-request.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ jobs:
1919
uses: actions/setup-go@v3
2020
with:
2121
go-version: 1.18.x
22-
- uses: dominikh/[email protected]
22+
- uses: dominikh/staticcheck-action@a3513ade2e5cb8075ba1c1ed1890a989cf0f2aa0 #v1.2.0
2323
with:
2424
version: "2022.1.1"
2525
test:
@@ -63,7 +63,7 @@ jobs:
6363
with:
6464
go-version: 1.18.x
6565
- name: Build
66-
uses: goreleaser/goreleaser-action@v3
66+
uses: goreleaser/goreleaser-action@ff11ca24a9b39f2d36796d1fbd7a4e39c182630a #v3
6767
with:
6868
version: v0.155.0
6969
args: --snapshot --skip-publish --debug

.github/workflows/release-dev.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -39,15 +39,15 @@ jobs:
3939
steps:
4040
- uses: actions/checkout@v3
4141
- name: Publish to Docker Hub
42-
uses: jerray/publish-docker-action@master
42+
uses: jerray/publish-docker-action@87d84711629b0dc9f6bb127b568413cc92a2088e #master@2022-10-14
4343
with:
4444
username: ${{ secrets.DOCKERHUB_USERNAME }}
4545
password: ${{ secrets.DOCKERHUB_PASSWORD }}
4646
file: dockerfiles/Dockerfile.self-contained
4747
repository: containrrr/watchtower
4848
tags: latest-dev
4949
- name: Publish to GHCR
50-
uses: jerray/publish-docker-action@master
50+
uses: jerray/publish-docker-action@87d84711629b0dc9f6bb127b568413cc92a2088e #master@2022-10-14
5151
with:
5252
username: ${{ secrets.BOT_USERNAME }}
5353
password: ${{ secrets.BOT_GHCR_PAT }}

.github/workflows/release.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -72,18 +72,18 @@ jobs:
7272
with:
7373
go-version: 1.18.x
7474
- name: Login to Docker Hub
75-
uses: docker/login-action@v2
75+
uses: docker/login-action@f4ef78c080cd8ba55a85445d5b36e214a81df20a #v2
7676
with:
7777
username: ${{ secrets.DOCKERHUB_USERNAME }}
7878
password: ${{ secrets.DOCKERHUB_TOKEN }}
7979
- name: Login to GHCR
80-
uses: docker/login-action@v2
80+
uses: docker/login-action@f4ef78c080cd8ba55a85445d5b36e214a81df20a #v2
8181
with:
8282
username: ${{ secrets.BOT_USERNAME }}
8383
password: ${{ secrets.BOT_GHCR_PAT }}
8484
registry: ghcr.io
8585
- name: Build
86-
uses: goreleaser/goreleaser-action@v3
86+
uses: goreleaser/goreleaser-action@ff11ca24a9b39f2d36796d1fbd7a4e39c182630a #v3
8787
with:
8888
version: v0.155.0
8989
args: --debug
@@ -193,7 +193,7 @@ jobs:
193193
runs-on: ubuntu-latest
194194
steps:
195195
- name: Pull new module version
196-
uses: andrewslotin/go-proxy-pull-action@master
196+
uses: andrewslotin/go-proxy-pull-action@bfc19ec6536e1638181b2ad6a03e16c7ccfb122f #master@2022-10-14
197197

198198

199199

0 commit comments

Comments
 (0)