File tree Expand file tree Collapse file tree 10 files changed +21
-21
lines changed Expand file tree Collapse file tree 10 files changed +21
-21
lines changed Original file line number Diff line number Diff line change @@ -44,15 +44,15 @@ jobs:
4444
4545 # TODO(#740): Workaround for go1.21 compatibility. Remove when GHA runners have Go 1.21+.
4646 - name : setup-go
47- uses : actions/setup-go@f111f3307d8850f501ac008e886eec1fd1932a34 # v5.3 .0
47+ uses : actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5.5 .0
4848 with :
4949 go-version-file : " go.mod"
5050 # not needed but gets rid of warnings
5151 cache : false
5252
5353 # Initializes the CodeQL tools for scanning.
5454 - name : Initialize CodeQL
55- uses : github/codeql-action/init@b6a472f63d85b9c78a3ac5e89422239fc15e9b3c # v3.28.1
55+ uses : github/codeql-action/init@76621b61decf072c1cee8dd1ce2d2a82d33c17ed # v3.29.8
5656 with :
5757 languages : ${{ matrix.language }}
5858 # If you wish to specify custom queries, you can do so here or in a config file.
6363 # Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
6464 # If this step fails, then you should remove it and run the build manually (see below)
6565 - name : Autobuild
66- uses : github/codeql-action/autobuild@b6a472f63d85b9c78a3ac5e89422239fc15e9b3c # v3.28.1
66+ uses : github/codeql-action/autobuild@76621b61decf072c1cee8dd1ce2d2a82d33c17ed # v3.29.8
6767 # Command-line programs to run using the OS shell.
6868 # 📚 https://git.io/JvXDl
6969
7676 # make release
7777
7878 - name : Perform CodeQL Analysis
79- uses : github/codeql-action/analyze@b6a472f63d85b9c78a3ac5e89422239fc15e9b3c # v3.28.1
79+ uses : github/codeql-action/analyze@76621b61decf072c1cee8dd1ce2d2a82d33c17ed # v3.29.8
Original file line number Diff line number Diff line change 1111 - name : ' Checkout Repository'
1212 uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
1313 - name : ' Dependency Review'
14- uses : actions/dependency-review-action@3b139cfc5fae8b618d3eae3675e383bb1769c019 # v4.5.0
14+ uses : actions/dependency-review-action@da24556b548a50705dd671f47852072ea4c105d9 # v4.7.1
Original file line number Diff line number Diff line change 1616 runs-on : ubuntu-latest
1717 # See https://github.com/orgs/community/discussions/26238.
1818 steps :
19- - uses : actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4.1.8
19+ - uses : actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
2020 with :
2121 name : event_name
2222 - name : Check event name
Original file line number Diff line number Diff line change 1414 - uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
1515
1616 - name : Set Node.js 20
17- uses : actions/setup-node@39370e3970a6d050c480ffad4ff0ed4d3fdee5af # v4.1 .0
17+ uses : actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4 .0
1818 with :
1919 node-version : 20
2020
3434 fi
3535
3636 # If index.js was different from expected, upload the expected version as an artifact
37- - uses : actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
37+ - uses : actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
3838 if : ${{ failure() && steps.diff.conclusion == 'failure' }}
3939 with :
4040 name : dist
Original file line number Diff line number Diff line change 1818 uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
1919
2020 - name : setup-go
21- uses : actions/setup-go@f111f3307d8850f501ac008e886eec1fd1932a34 # v5.3 .0
21+ uses : actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5.5 .0
2222 with :
2323 go-version-file : " go.mod"
2424 # not needed but gets rid of warnings
3030 run : |
3131 echo "$EVENT_NAME" > ./event_name.txt
3232
33- - uses : actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
33+ - uses : actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
3434 with :
3535 name : event_name
3636 path : ./event_name.txt
Original file line number Diff line number Diff line change 1616 path : __THIS_REPO__
1717
1818 - name : setup-go
19- uses : actions/setup-go@f111f3307d8850f501ac008e886eec1fd1932a34 # v5.3 .0
19+ uses : actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5.5 .0
2020 with :
2121 go-version-file : " __THIS_REPO__/go.mod"
2222 # not needed but gets rid of warnings
Original file line number Diff line number Diff line change @@ -11,12 +11,12 @@ jobs:
1111 runs-on : ubuntu-latest
1212 steps :
1313 - uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
14- - uses : actions/setup-go@f111f3307d8850f501ac008e886eec1fd1932a34 # v5.3 .0
14+ - uses : actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5.5 .0
1515 with :
1616 go-version-file : " go.mod"
1717 # not needed but gets rid of warnings
1818 cache : false
19- - uses : golangci/golangci-lint-action@ec5d18412c0aeab7936cb16880d708ba2a64e1ae # v6.2.0
19+ - uses : golangci/golangci-lint-action@55c2c1448f86e01eaae002a5a3a9624417608d84 # v6.5.2
2020 name : golangci-lint
2121 with :
2222 # Require: The version of golangci-lint to use.
4141 runs-on : ubuntu-latest
4242 steps :
4343 - uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
44- - uses : actions/setup-node@39370e3970a6d050c480ffad4ff0ed4d3fdee5af # v4.1 .0
44+ - uses : actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4 .0
4545 with :
4646 node-version : 20
4747 - run : make eslint
5050 runs-on : ubuntu-latest
5151 steps :
5252 - uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
53- - uses : actions/setup-node@39370e3970a6d050c480ffad4ff0ed4d3fdee5af # v4.1 .0
53+ - uses : actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4 .0
5454 with :
5555 node-version : 20
5656 - run : make renovate-config-validator
Original file line number Diff line number Diff line change 6363 permissions : read-all
6464 steps :
6565 - name : Install the verifier
66- uses : slsa-framework/slsa-verifier/actions/installer@3714a2a4684014deb874a0e737dffa0ee02dd647 # v2.6.0
66+ uses : slsa-framework/slsa-verifier/actions/installer@ea584f4502babc6f60d9bc799dbbb13c1caa9ee6 # v2.7.1
6767
6868 - name : Download assets
6969 env :
Original file line number Diff line number Diff line change 3030 persist-credentials : false
3131
3232 - name : " Run analysis"
33- uses : ossf/scorecard-action@62b2cac7ed8198b15735ed49ab1e5cf35480ba46 # v2.4.0
33+ uses : ossf/scorecard-action@05b42c624433fc40578a4040d5cf5e36ddca8cde # v2.4.2
3434 with :
3535 results_file : results.sarif
3636 results_format : sarif
@@ -49,14 +49,14 @@ jobs:
4949 # Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
5050 # format to the repository Actions tab.
5151 - name : " Upload artifact"
52- uses : actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
52+ uses : actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
5353 with :
5454 name : SARIF file
5555 path : results.sarif
5656 retention-days : 5
5757
5858 # Upload the results to GitHub's code scanning dashboard.
5959 - name : " Upload to code-scanning"
60- uses : github/codeql-action/upload-sarif@b6a472f63d85b9c78a3ac5e89422239fc15e9b3c # v3.28.1
60+ uses : github/codeql-action/upload-sarif@76621b61decf072c1cee8dd1ce2d2a82d33c17ed # v3.29.8
6161 with :
6262 sarif_file : results.sarif
Original file line number Diff line number Diff line change 5757 [ -z "$(cat changes.patch)" ] && RESULT=false || RESULT=true
5858 echo "patch_not_empty=$RESULT" >> "$GITHUB_OUTPUT"
5959 - name : upload
60- uses : actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
60+ uses : actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
6161 with :
6262 name : changes.patch
6363 path : changes.patch
7979 PR_NUMBER : ${{ inputs.pr_number }}
8080 run : gh pr checkout "$PR_NUMBER"
8181 - name : download-patch
82- uses : actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4.1.8
82+ uses : actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
8383 with :
8484 name : changes.patch
8585 - id : apply
You can’t perform that action at this time.
0 commit comments