Skip to content

Commit b4e2cf2

Browse files
committed
CI: update+pin actions by hash
1 parent 349523d commit b4e2cf2

File tree

5 files changed

+24
-24
lines changed

5 files changed

+24
-24
lines changed

.github/workflows/create-new-tag.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ jobs:
1212
bump_version:
1313
runs-on: ubuntu-latest
1414
steps:
15-
- uses: actions/checkout@v3
15+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
1616
with:
1717
fetch-depth: 2
1818

@@ -23,7 +23,7 @@ jobs:
2323
2424
- name: Patch Package Versions when code change.
2525
id: patch-version
26-
uses: anothrNick/github-tag-action@v1
26+
uses: anothrNick/github-tag-action@4ed44965e0db8dab2b466a16da04aec3cc312fd8 # 1.75.0
2727
env:
2828
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
2929
DEFAULT_BUMP: patch

.github/workflows/main.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -29,18 +29,18 @@ jobs:
2929
&& github.event.workflow_run.conclusion == 'success')
3030
runs-on: ubuntu-latest
3131
steps:
32-
- uses: actions/checkout@v4
32+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
3333
with:
3434
fetch-depth: 0
3535

36-
- uses: actions/cache@v4
36+
- uses: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809 # v4.2.4
3737
id: wheels_cache
3838
with:
3939
path: ./wheels
4040
key: wheels-${{ github.sha }}
4141

4242
- name: Setup Python
43-
uses: actions/setup-python@v5
43+
uses: actions/setup-python@e797f83bcb11b83ae66e0230d6156d7c80228e7c # v6.0.0
4444
with:
4545
python-version: "3.10"
4646

@@ -82,7 +82,7 @@ jobs:
8282
- build-wheels
8383

8484
steps:
85-
- uses: actions/checkout@v4
85+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
8686

8787
- name: Install Dependencies
8888
shell: bash
@@ -98,7 +98,7 @@ jobs:
9898
pip freeze
9999
100100
- name: Get Wheels from Cache
101-
uses: actions/cache@v4
101+
uses: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809 # v4.2.4
102102
id: wheels_cache
103103
with:
104104
path: ./wheels
@@ -147,7 +147,7 @@ jobs:
147147
if: |
148148
github.repository == 'opendatacube/odc-stats'
149149
150-
uses: codecov/codecov-action@v4
150+
uses: codecov/codecov-action@5a1091511ad55cbe89839c7260b706298ca349f7 # v5.5.1
151151
with:
152152
token: ${{ secrets.CODECOV_TOKEN }}
153153
fail_ci_if_error: false

.github/workflows/publish-new-version.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -14,15 +14,15 @@ jobs:
1414
&& github.event.workflow_run.conclusion == 'success'
1515
runs-on: ubuntu-latest
1616
steps:
17-
- uses: actions/checkout@v4
18-
- uses: actions/cache@v4
17+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
18+
- uses: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809 # v4.2.4
1919
id: wheels_cache
2020
with:
2121
path: ./wheels
2222
key: wheels-${{ github.sha }}
2323

2424
- name: Setup Python
25-
uses: actions/setup-python@v5
25+
uses: actions/setup-python@e797f83bcb11b83ae66e0230d6156d7c80228e7c # v6.0.0
2626
with:
2727
python-version: "3.10"
2828

@@ -51,8 +51,8 @@ jobs:
5151
&& github.event.workflow_run.conclusion == 'success'
5252
runs-on: ubuntu-latest
5353
steps:
54-
- uses: actions/checkout@v4
55-
- uses: actions/cache@v4
54+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
55+
- uses: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809 # v4.2.4
5656
id: wheels_cache
5757
with:
5858
path: ./wheels

.github/workflows/statistician-dive.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -26,10 +26,10 @@ jobs:
2626
name: Analyze image efficiency
2727
steps:
2828
- name: Checkout
29-
uses: actions/checkout@v3
29+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
3030

3131
- name: lint
32-
uses: luke142367/Docker-Lint-Action@v1.1.1
32+
uses: luke142367/Docker-Lint-Action@5c4c86226f39785a66827bbc2e322600c9afa3a9 # v1.1.1
3333
with:
3434
target: docker/Dockerfile
3535
env:
@@ -47,7 +47,7 @@ jobs:
4747
wagoodman/dive:v0.12.0 --ci-config /.dive-ci ${ORG}/${IMAGE}:_build
4848
4949
- name: Docker image size check
50-
uses: wemake-services/docker-image-size-limit@2.0.0
50+
uses: wemake-services/docker-image-size-limit@cbc4fff807e8d490ec7d808c52991387649ffa65 # 2.1.0
5151
with:
5252
image: ${{ env.ORG }}/${{ env.IMAGE}}:_build
5353
size: "3 GiB"

.github/workflows/statistician-image.yml

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -31,10 +31,10 @@ jobs:
3131
runs-on: ubuntu-latest
3232
steps:
3333
- name: Checkout code
34-
uses: actions/checkout@v3
34+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
3535

3636
- name: lint Dockerfile
37-
uses: hadolint/hadolint-action@v2.0.0
37+
uses: hadolint/hadolint-action@3fc49fb50d59c6ab7917a2e4195dba633e515b29 # v3.2.0
3838
with:
3939
dockerfile: docker/Dockerfile
4040
ignore: DL3008,DL3002,DL3013,DL3059,SC2102
@@ -59,7 +59,7 @@ jobs:
5959
runs-on: ubuntu-latest
6060
steps:
6161
- name: Checkout code
62-
uses: actions/checkout@v3
62+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
6363

6464
- name: Build a new docker image with tag
6565
id: tag-image
@@ -76,16 +76,16 @@ jobs:
7676
runs-on: ubuntu-latest
7777
steps:
7878
- name: Checkout code
79-
uses: actions/checkout@v3
79+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
8080

8181
- name: Configure AWS credentials
82-
uses: aws-actions/configure-aws-credentials@v1
82+
uses: aws-actions/configure-aws-credentials@a03048d87541d1d9fcf2ecf528a4a65ba9bd7838 # v5.0.0
8383
with:
8484
role-to-assume: arn:aws:iam::538673716275:role/github-actions-role
8585
aws-region: ap-southeast-2
8686

8787
- name: Push image to ECR
88-
uses: whoan/docker-build-with-cache-action@master
88+
uses: whoan/docker-build-with-cache-action@d8d3ad518e7ac382b880720d0751815e656fe032 # v8.1.0
8989
with:
9090
context: ./docker
9191
registry: 538673716275.dkr.ecr.ap-southeast-2.amazonaws.com
@@ -101,10 +101,10 @@ jobs:
101101

102102
steps:
103103
- name: Checkout code
104-
uses: actions/checkout@v3
104+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
105105

106106
- name: Push image to ghcr
107-
uses: whoan/docker-build-with-cache-action@master
107+
uses: whoan/docker-build-with-cache-action@d8d3ad518e7ac382b880720d0751815e656fe032 # v8.1.0
108108
with:
109109
context: ./docker
110110
registry: ghcr.io

0 commit comments

Comments
 (0)