Skip to content

Commit 8116d20

Browse files
authored
chore: pin third-party GitHub Actions to commit SHAs (#411)
1 parent d05fccf commit 8116d20

File tree

2 files changed

+7
-7
lines changed

2 files changed

+7
-7
lines changed

.github/workflows/manual-publish.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ jobs:
2424
python-version: "3.10"
2525

2626
- name: Install poetry
27-
uses: abatilo/actions-poetry@7b6d33e44b4f08d7021a1dee3c044e9c253d6439
27+
uses: abatilo/actions-poetry@7b6d33e44b4f08d7021a1dee3c044e9c253d6439 # v3.0.0
2828

2929
- uses: launchdarkly/gh-actions/actions/release-secrets@release-secrets-v1.2.0
3030
name: "Get PyPI token"
@@ -37,7 +37,7 @@ jobs:
3737

3838
- name: Publish package distributions to PyPI
3939
if: ${{ inputs.dry_run == false }}
40-
uses: pypa/gh-action-pypi-publish@release/v1
40+
uses: pypa/gh-action-pypi-publish@ed0c53931b1dc9bd32cbe73a98c7f6766f8a527e # v1.13.0
4141
with:
4242
password: ${{env.PYPI_AUTH_TOKEN}}
4343

@@ -47,7 +47,7 @@ jobs:
4747
actions: read
4848
id-token: write
4949
contents: write
50-
uses: slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@v2.0.0
50+
uses: slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@5a775b367a56d5bd118a224a811bba288150a563 # v2.0.0
5151
with:
5252
base64-subjects: "${{ needs.build-publish.outputs.package-hashes }}"
5353
upload-assets: ${{ !inputs.dry_run }}

.github/workflows/release-please.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@ jobs:
1616
upload-tag-name: ${{ steps.release.outputs.tag_name }}
1717
package-hashes: ${{ steps.build.outputs.package-hashes}}
1818
steps:
19-
- uses: googleapis/release-please-action@v4
19+
- uses: googleapis/release-please-action@16a9c90856f42705d54a6fda1823352bdc62cf38 # v4.4.0
2020
id: release
2121

2222
- uses: actions/checkout@v4
@@ -31,7 +31,7 @@ jobs:
3131

3232
- name: Install poetry
3333
if: ${{ steps.release.outputs.releases_created == 'true' }}
34-
uses: abatilo/actions-poetry@7b6d33e44b4f08d7021a1dee3c044e9c253d6439
34+
uses: abatilo/actions-poetry@7b6d33e44b4f08d7021a1dee3c044e9c253d6439 # v3.0.0
3535

3636
- uses: launchdarkly/gh-actions/actions/release-secrets@release-secrets-v1.2.0
3737
if: ${{ steps.release.outputs.releases_created == 'true' }}
@@ -49,7 +49,7 @@ jobs:
4949

5050
- name: Publish package distributions to PyPI
5151
if: ${{ steps.release.outputs.releases_created == 'true' }}
52-
uses: pypa/gh-action-pypi-publish@release/v1
52+
uses: pypa/gh-action-pypi-publish@ed0c53931b1dc9bd32cbe73a98c7f6766f8a527e # v1.13.0
5353
with:
5454
password: ${{env.PYPI_AUTH_TOKEN}}
5555

@@ -60,7 +60,7 @@ jobs:
6060
actions: read
6161
id-token: write
6262
contents: write
63-
uses: slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@v2.0.0
63+
uses: slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@5a775b367a56d5bd118a224a811bba288150a563 # v2.0.0
6464
with:
6565
base64-subjects: "${{ needs.release-package.outputs.package-hashes }}"
6666
upload-assets: true

0 commit comments

Comments
 (0)