Skip to content

Commit 11452d4

Browse files
authored
INTPYTHON-608 Use pinned sources for GitHub Actions (#199)
1 parent 648b8fc commit 11452d4

File tree

3 files changed

+13
-13
lines changed

3 files changed

+13
-13
lines changed

.github/workflows/release-python.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -77,7 +77,7 @@ jobs:
7777
path: dist/
7878
- name: Publish distribution 📦 to PyPI
7979
if: startsWith(env.DRY_RUN, 'false')
80-
uses: pypa/gh-action-pypi-publish@release/v1
80+
uses: pypa/gh-action-pypi-publish@76f52bc884231f62b9a034ebfe128415bbaabdfc # release/v1
8181

8282
post-publish:
8383
needs: [publish]

.github/workflows/test-python.yml

+10-10
Original file line numberDiff line numberDiff line change
@@ -27,11 +27,11 @@ jobs:
2727
persist-credentials: false
2828
fetch-depth: 0
2929
- name: Install uv
30-
uses: astral-sh/setup-uv@v5
30+
uses: astral-sh/setup-uv@d4b2f3b6ecc6e67c4457f6d3e41ec42d3d0fcb86 # v5
3131
with:
3232
enable-cache: true
3333
python-version: ${{ matrix.python-version }}
34-
- uses: extractions/setup-just@v3
34+
- uses: extractions/setup-just@e33e0265a09d6d736e2ee1e0eb685ef1de4669ff # v3
3535
- run: just install
3636
- run: just lint
3737
- run: just docs
@@ -50,14 +50,14 @@ jobs:
5050
persist-credentials: false
5151
fetch-depth: 0
5252
- name: Install uv
53-
uses: astral-sh/setup-uv@v5
53+
uses: astral-sh/setup-uv@d4b2f3b6ecc6e67c4457f6d3e41ec42d3d0fcb86 # v5
5454
with:
5555
enable-cache: true
5656
python-version: ${{ matrix.python-version }}
57-
- uses: extractions/setup-just@v3
57+
- uses: extractions/setup-just@e33e0265a09d6d736e2ee1e0eb685ef1de4669ff # v3
5858
- name: Start MongoDB on Linux
5959
if: ${{ startsWith(runner.os, 'Linux') }}
60-
uses: supercharge/[email protected]
60+
uses: supercharge/mongodb-github-action@90004df786821b6308fb02299e5835d0dae05d0d # 1.12.0
6161
with:
6262
mongodb-version: ${{ env.MAX_MONGODB }}
6363
mongodb-replica-set: test-rs
@@ -86,18 +86,18 @@ jobs:
8686
persist-credentials: false
8787
fetch-depth: 0
8888
- name: Install uv
89-
uses: astral-sh/setup-uv@v5
89+
uses: astral-sh/setup-uv@d4b2f3b6ecc6e67c4457f6d3e41ec42d3d0fcb86 # v5
9090
with:
9191
enable-cache: true
9292
python-version: ${{ env.MIN_PYTHON }}
93-
- uses: extractions/setup-just@v3
93+
- uses: extractions/setup-just@e33e0265a09d6d736e2ee1e0eb685ef1de4669ff # v3
9494
- name: Install uv
95-
uses: astral-sh/setup-uv@v5
95+
uses: astral-sh/setup-uv@d4b2f3b6ecc6e67c4457f6d3e41ec42d3d0fcb86 # v5
9696
with:
9797
enable-cache: true
9898
python-version: ${{ env.MIN_PYTHON }}
99-
- uses: extractions/setup-just@v3
100-
- uses: supercharge/[email protected]
99+
- uses: extractions/setup-just@e33e0265a09d6d736e2ee1e0eb685ef1de4669ff # v3
100+
- uses: supercharge/mongodb-github-action@90004df786821b6308fb02299e5835d0dae05d0d # 1.12.0
101101
with:
102102
mongodb-version: ${{ env.MIN_MONGODB }}
103103
mongodb-replica-set: test-rs

.github/workflows/zizmor.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -18,15 +18,15 @@ jobs:
1818
with:
1919
persist-credentials: false
2020
- name: Setup Rust
21-
uses: actions-rust-lang/setup-rust-toolchain@v1
21+
uses: actions-rust-lang/setup-rust-toolchain@9d7e65c320fdb52dcd45ffaa68deb6c02c8754d9 # v1
2222
- name: Get zizmor
2323
run: cargo install zizmor
2424
- name: Run zizmor
2525
run: zizmor --format sarif . > results.sarif
2626
env:
2727
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
2828
- name: Upload SARIF file
29-
uses: github/codeql-action/upload-sarif@v3
29+
uses: github/codeql-action/upload-sarif@28deaeda66b76a05916b6923827895f2b14ab387 # v3
3030
with:
3131
sarif_file: results.sarif
3232
category: zizmor

0 commit comments

Comments
 (0)