mirror of
https://github.com/gesellix/Bose-SoundTouch.git
synced 2026-08-19 00:56:16 +00:00
Replace floating major-tag references (uses: foo/bar@vN) with the specific commit SHAs they currently resolve to, annotated with the fully-versioned tag (# vX.Y.Z) for human readability. Pinning to a SHA makes the action behaviour reproducible across runs and removes the supply-chain risk of a maintainer (or attacker) moving a tag to a new commit. One documented exception: semgrep/semgrep-action does not publish v1.x.y semver tags — v1 is their only canonical release name on that line — so it keeps a "# v1" annotation with an inline explanation. actions/dependency-review-action's previous "@v5" reference would have failed at run time: that repo only ships fully-versioned tags (v5.0.0), no moving v5 alias. Pinned to v5.0.0 explicitly. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
38 lines
1.0 KiB
YAML
38 lines
1.0 KiB
YAML
name: Deploy Documentation
|
|
on:
|
|
push:
|
|
branches:
|
|
- main
|
|
paths:
|
|
- 'docs/**'
|
|
workflow_dispatch:
|
|
|
|
permissions:
|
|
contents: read
|
|
pages: write
|
|
id-token: write
|
|
|
|
jobs:
|
|
deploy:
|
|
environment:
|
|
name: github-pages
|
|
url: ${{ steps.deployment.outputs.page_url }}
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
- name: Setup Pages
|
|
uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6.0.0
|
|
- name: Build with Jekyll
|
|
uses: actions/jekyll-build-pages@44a6e6beabd48582f863aeeb6cb2151cc1716697 # v1.0.13
|
|
with:
|
|
source: 'docs/'
|
|
destination: '_site'
|
|
- name: Upload artifact
|
|
uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0
|
|
with:
|
|
path: '_site'
|
|
- name: Deploy to GitHub Pages
|
|
id: deployment
|
|
uses: actions/deploy-pages@cd2ce8fcbc39b97be8ca5fce6e763baed58fa128 # v5.0.0
|