Skip to content

Commit 11b1a5f

Browse files
chore(deps): pin dependencies
1 parent 29ffbfa commit 11b1a5f

File tree

5 files changed

+13
-13
lines changed

5 files changed

+13
-13
lines changed

.github/workflows/api-check.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ jobs:
2020
OS_DOMAIN: apps.silver.devops.gov.bc.ca
2121
GTW_DOMAIN: api.gov.bc.ca
2222
steps:
23-
- uses: actions/checkout@v5
23+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
2424

2525
- name: Postman Smoke Test on API Gateway
2626
uses: matt-ball/newman-action@master

.github/workflows/merge.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,7 @@ jobs:
4141
environment:
4242
name: test
4343
steps:
44-
- uses: actions/checkout@v5
44+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
4545
- name: Deploys
4646
uses: bcgov/action-deployer-openshift@d972993c70aba88e4f2fe66a66c4b7149fa9fcad # v4.0.0
4747
with:
@@ -84,7 +84,7 @@ jobs:
8484
environment:
8585
name: prod
8686
steps:
87-
- uses: actions/checkout@v5
87+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
8888

8989
- name: Deploys
9090
uses: bcgov/action-deployer-openshift@d972993c70aba88e4f2fe66a66c4b7149fa9fcad # v4.0.0

.github/workflows/pr-open.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -20,10 +20,10 @@ jobs:
2020
outputs:
2121
semver: ${{ steps.changelog.outputs.tag }}
2222
steps:
23-
- uses: actions/checkout@v5
23+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
2424

2525
- name: Pull request size and stability labels
26-
uses: actions/labeler@v6
26+
uses: actions/labeler@634933edcd8ababfe52f92936142cc22ac488b1b # v6
2727
continue-on-error: true
2828
with:
2929
repo-token: "${{ secrets.GITHUB_TOKEN }}"
@@ -145,7 +145,7 @@ jobs:
145145
checks: write
146146
pull-requests: write
147147
steps:
148-
- uses: actions/checkout@v5
148+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
149149
- name: API Health check
150150
uses: matt-ball/newman-action@master
151151
with:

.github/workflows/reusable-tests-be.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@ jobs:
2828

2929
- name: Archive CycloneDX
3030
continue-on-error: true
31-
uses: actions/upload-artifact@v4
31+
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
3232
with:
3333
name: cyclone-backend
3434
path: target/bom.json

.github/workflows/reusable-tests-repo.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ jobs:
99
if: github.event_name != 'pull_request' || !github.event.pull_request.draft
1010
runs-on: ubuntu-24.04
1111
steps:
12-
- uses: actions/checkout@v5
12+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
1313
- name: Run Trivy vulnerability scanner in repo mode
1414
uses: aquasecurity/trivy-action@b6643a29fecd7f34b3597bc6acb0a98b03d33ff8 # 0.33.1
1515
with:
@@ -21,7 +21,7 @@ jobs:
2121
severity: "CRITICAL,HIGH"
2222

2323
- name: Upload Trivy scan results to GitHub Security tab
24-
uses: github/codeql-action/upload-sarif@v3
24+
uses: github/codeql-action/upload-sarif@192325c86100d080feab897ff886c34abd4c83a3 # v3
2525
with:
2626
sarif_file: "trivy-results.sarif"
2727

@@ -33,14 +33,14 @@ jobs:
3333
contents: read
3434
security-events: write
3535
steps:
36-
- uses: actions/checkout@v5
37-
- uses: github/codeql-action/init@v3
36+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
37+
- uses: github/codeql-action/init@192325c86100d080feab897ff886c34abd4c83a3 # v3
3838
with:
3939
languages: javascript,java
4040

4141
# Autobuild failed for Java, so building manually
4242
- name: Set up JDK 17 and Caching maven dependencies
43-
uses: actions/setup-java@v5
43+
uses: actions/setup-java@dded0888837ed1f317902acf8a20df0ad188d165 # v5
4444
with:
4545
distribution: "temurin"
4646
java-version: "17"
@@ -51,4 +51,4 @@ jobs:
5151
run: ./mvnw clean package
5252

5353
- name: Perform CodeQL Analysis
54-
uses: github/codeql-action/analyze@v3
54+
uses: github/codeql-action/analyze@192325c86100d080feab897ff886c34abd4c83a3 # v3

0 commit comments

Comments
 (0)