diff --git a/.github/workflows/codeql.yaml b/.github/workflows/codeql.yaml index 0729739..b71b57d 100644 --- a/.github/workflows/codeql.yaml +++ b/.github/workflows/codeql.yaml @@ -46,11 +46,11 @@ jobs: with: go-version-file: go.mod - - uses: github/codeql-action/init@9e0d7b8d25671d64c341c19c0152d693099fb5ba # v4 + - uses: github/codeql-action/init@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v4 with: languages: ${{ matrix.language }} config-file: ./.github/codeql/codeql-config.yml - - uses: github/codeql-action/analyze@9e0d7b8d25671d64c341c19c0152d693099fb5ba # v4 + - uses: github/codeql-action/analyze@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v4 with: category: "/language:${{ matrix.language }}" diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index eb5f35d..ce30dcf 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -151,12 +151,12 @@ jobs: # execution — but binfmt registration is needed so buildx # recognises linux/arm64 and linux/riscv64 as valid platforms. - uses: docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a # v4 - - uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4 + - uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4 # Logins for the three image registries. Quay/Docker Hub are # skipped if their token is missing, mirroring the previous # workflow's per-registry opt-in pattern. - - uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4 + - uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4 with: registry: ghcr.io username: ${{ github.actor }} @@ -165,7 +165,7 @@ jobs: env: QUAY_TOKEN: ${{ secrets.QUAY_TOKEN }} if: env.QUAY_TOKEN != '' - uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4 + uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4 with: registry: quay.io username: ${{ secrets.QUAY_USERNAME }} @@ -174,7 +174,7 @@ jobs: env: DOCKERHUB_TOKEN: ${{ secrets.DOCKERHUB_TOKEN }} if: env.DOCKERHUB_TOKEN != '' - uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4 + uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4 with: username: ${{ secrets.DOCKERHUB_USERNAME }} password: ${{ secrets.DOCKERHUB_TOKEN }} @@ -182,7 +182,7 @@ jobs: - uses: sigstore/cosign-installer@cad07c2e89fa2edd6e2d7bab4c1aa38e53f76003 # v4 - uses: anchore/sbom-action/download-syft@e22c389904149dbc22b58101806040fa8d37a610 # v0 - - uses: goreleaser/goreleaser-action@1a80836c5c9d9e5755a25cb59ec6f45a3b5f41a8 # v7 + - uses: goreleaser/goreleaser-action@5daf1e915a5f0af01ddbcd89a43b8061ff4f1a89 # v7 with: version: "v2.16.0" args: release --clean diff --git a/.github/workflows/scorecard.yaml b/.github/workflows/scorecard.yaml index e911e0d..729b9ab 100644 --- a/.github/workflows/scorecard.yaml +++ b/.github/workflows/scorecard.yaml @@ -57,6 +57,6 @@ jobs: # Surface findings as alerts in the repo's Security tab. The # upload-sarif action lives under the codeql-action repo but # works for any tool's SARIF output — it isn't tied to CodeQL. - - uses: github/codeql-action/upload-sarif@9e0d7b8d25671d64c341c19c0152d693099fb5ba # v4 + - uses: github/codeql-action/upload-sarif@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v4 with: sarif_file: results.sarif