Skip to content

Commit e044099

Browse files
committed
ci: Bump actions versions and pin them to SHAs
1 parent 0ca69c7 commit e044099

File tree

7 files changed

+39
-39
lines changed

7 files changed

+39
-39
lines changed

.github/workflows/ci-chart.yaml

+5-5
Original file line numberDiff line numberDiff line change
@@ -28,21 +28,21 @@ jobs:
2828
runs-on: ubuntu-latest
2929
steps:
3030
- name: Checkout
31-
uses: actions/checkout@v3
31+
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
3232
with:
3333
fetch-depth: 0
3434
- name: Set up Helm
35-
uses: azure/setup-helm@v3
35+
uses: azure/setup-helm@5119fcb9089d432beecbf79bb2c7915207344b78 # v3.5
3636
with:
3737
version: v3.10.1
3838
- name: Set up Python
39-
uses: actions/setup-python@v4
39+
uses: actions/setup-python@65d7f2d534ac1bc67fcd62888c5f4f3d2cb2b236 # v4.7.1
4040
with:
4141
python-version: "3.10"
4242
check-latest: true
4343
- name: Set up chart-testing
44-
uses: helm/chart-testing-action@v2.3.1
44+
uses: helm/chart-testing-action@e6669bcd63d7cb57cb4380c33043eebe5d111992 # v2.6.1
4545
- name: Create k8s kind cluster
46-
uses: helm/kind-action@v1.3.0
46+
uses: helm/kind-action@dda0770415bac9fc20092cacbc54aa298604d140 # v1.8.0
4747
- name: Lint and install
4848
run: make lint-and-install-chart

.github/workflows/ci.yaml

+8-8
Original file line numberDiff line numberDiff line change
@@ -21,9 +21,9 @@ jobs:
2121
contents: read # for actions/checkout to fetch code
2222
steps:
2323
- name: Checkout
24-
uses: actions/checkout@v3
24+
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
2525
- name: Setup
26-
uses: actions/setup-go@v4
26+
uses: actions/setup-go@93397bea11091df50f3d7e59dc26a7711a8bcfbe # v4.1.0
2727
with:
2828
go-version: 1.20.x
2929
cache: true
@@ -44,9 +44,9 @@ jobs:
4444
contents: read # for actions/checkout to fetch code
4545
steps:
4646
- name: Checkout
47-
uses: actions/checkout@v3
47+
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
4848
- name: Setup
49-
uses: actions/setup-go@v4
49+
uses: actions/setup-go@93397bea11091df50f3d7e59dc26a7711a8bcfbe # v4.1.0
5050
with:
5151
go-version: 1.20.x
5252
cache: true
@@ -62,9 +62,9 @@ jobs:
6262
contents: read # for actions/checkout to fetch code
6363
steps:
6464
- name: Checkout
65-
uses: actions/checkout@v3
65+
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
6666
- name: Setup
67-
uses: actions/setup-go@v4
67+
uses: actions/setup-go@93397bea11091df50f3d7e59dc26a7711a8bcfbe # v4.1.0
6868
with:
6969
go-version: 1.20.x
7070
cache: true
@@ -80,9 +80,9 @@ jobs:
8080
contents: read # for actions/checkout to fetch code
8181
steps:
8282
- name: Checkout
83-
uses: actions/checkout@v3
83+
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
8484
- name: Setup
85-
uses: actions/setup-go@v4
85+
uses: actions/setup-go@93397bea11091df50f3d7e59dc26a7711a8bcfbe # v4.1.0
8686
with:
8787
go-version: 1.20.x
8888
cache: true

.github/workflows/e2e.yaml

+3-3
Original file line numberDiff line numberDiff line change
@@ -17,13 +17,13 @@ jobs:
1717
runs-on: ubuntu-latest
1818
steps:
1919
- name: Checkout
20-
uses: actions/checkout@v3
20+
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
2121
- name: Setup | Go
22-
uses: actions/setup-go@v4
22+
uses: actions/setup-go@93397bea11091df50f3d7e59dc26a7711a8bcfbe # v4.1.0
2323
with:
2424
go-version: 1.20.x
2525
- name: Setup | Kubernetes Cluster
26-
uses: helm/kind-action@v1.5.0
26+
uses: helm/kind-action@dda0770415bac9fc20092cacbc54aa298604d140 # v1.8.0
2727
with:
2828
version: v0.18.0
2929
cluster_name: pipeline-controller

.github/workflows/release-chart.yaml

+2-2
Original file line numberDiff line numberDiff line change
@@ -15,9 +15,9 @@ jobs:
1515
runs-on: ubuntu-latest
1616
steps:
1717
- name: Checkout
18-
uses: actions/checkout@v3
18+
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
1919
- name: Login to GitHub Container Registry
20-
uses: docker/login-action@v2
20+
uses: docker/login-action@343f7c4344506bcbf9b4de18042ae17996df046d # v3.0.0
2121
with:
2222
registry: ghcr.io
2323
username: ${{ github.actor }}

.github/workflows/release-pr.yaml

+5-5
Original file line numberDiff line numberDiff line change
@@ -14,20 +14,20 @@ jobs:
1414
uses: xt0rted/pull-request-comment-branch@v2
1515
id: comment-branch
1616
- name: Checkout
17-
uses: actions/checkout@v3
17+
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
1818
with:
1919
ref: ${{ steps.comment-branch.outputs.head_ref }}
2020
- name: Setup
21-
uses: actions/setup-go@v4
21+
uses: actions/setup-go@93397bea11091df50f3d7e59dc26a7711a8bcfbe # v4.1.0
2222
with:
2323
go-version: 1.20.x
2424
cache: true
2525
- name: Setup QEMU
26-
uses: docker/setup-qemu-action@v2
26+
uses: docker/setup-qemu-action@68827325e0b33c7199eb31dd4e31fbe9023e06e3 # v3.0.0
2727
- name: Setup Docker Buildx
28-
uses: docker/setup-buildx-action@v2
28+
uses: docker/setup-buildx-action@f95db51fddba0c2d1ec667646a06c2ce06100226 # v3.0.0
2929
- name: Login to GitHub Container Registry
30-
uses: docker/login-action@v2
30+
uses: docker/login-action@343f7c4344506bcbf9b4de18042ae17996df046d # v3.0.0
3131
with:
3232
registry: ghcr.io
3333
username: ${{ github.actor }}

.github/workflows/release.yaml

+6-6
Original file line numberDiff line numberDiff line change
@@ -10,24 +10,24 @@ jobs:
1010
runs-on: ubuntu-latest
1111
steps:
1212
- name: Checkout
13-
uses: actions/checkout@v3
13+
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
1414
- name: Setup
15-
uses: actions/setup-go@v4
15+
uses: actions/setup-go@93397bea11091df50f3d7e59dc26a7711a8bcfbe # v4.1.0
1616
with:
1717
go-version: 1.20.x
1818
cache: true
1919
- name: Setup QEMU
20-
uses: docker/setup-qemu-action@v2
20+
uses: docker/setup-qemu-action@68827325e0b33c7199eb31dd4e31fbe9023e06e3 # v3.0.0
2121
- name: Setup Docker Buildx
22-
uses: docker/setup-buildx-action@v2
22+
uses: docker/setup-buildx-action@f95db51fddba0c2d1ec667646a06c2ce06100226 # v3.0.0
2323
- name: Login to GitHub Container Registry
24-
uses: docker/login-action@v2
24+
uses: docker/login-action@343f7c4344506bcbf9b4de18042ae17996df046d # v3.0.0
2525
with:
2626
registry: ghcr.io
2727
username: ${{ github.actor }}
2828
password: ${{ secrets.GHCR_TOKEN }}
2929
- name: Login to DockerHub
30-
uses: docker/login-action@v2
30+
uses: docker/login-action@343f7c4344506bcbf9b4de18042ae17996df046d # v3.0.0
3131
with:
3232
username: ${{ secrets.DOCKERHUB_USERNAME }}
3333
password: ${{ secrets.DOCKERHUB_PASSWORD }}

.github/workflows/update-chart.yaml

+10-10
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ jobs:
99
runs-on: ubuntu-latest
1010
steps:
1111
- name: Checkout
12-
uses: actions/checkout@v3
12+
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
1313
- name: Import GPG key for signing commits
1414
run: |
1515
echo -n "$GPG_SIGNING_KEY" | gpg --import
@@ -19,24 +19,24 @@ jobs:
1919
env:
2020
GPG_SIGNING_KEY: ${{ secrets.GPG_SIGNING_KEY }}
2121
- name: bump app version
22-
uses: mikefarah/yq@v4.30.4
22+
uses: mikefarah/yq@a198f72367ce9da70b564a2cc25399de8e27bf37 # v4.35.2
2323
with:
2424
cmd: yq -i '.appVersion = "${{ github.event.registry_package.package_version.container_metadata.tag.name }}"' charts/pipeline-controller/Chart.yaml
2525
- name: get chart version
2626
id: get_chart_version
27-
uses: mikefarah/yq@v4.30.4
27+
uses: mikefarah/yq@a198f72367ce9da70b564a2cc25399de8e27bf37 # v4.35.2
2828
with:
2929
cmd: yq '.version' charts/pipeline-controller/Chart.yaml
3030
- name: increment chart version
3131
id: inc_chart_version
3232
run: echo NEW_CHART_VERSION=$(echo ${{ steps.get_chart_version.outputs.result }} | awk -F. -v OFS=. '{print $1,++$2,0}') >> $GITHUB_OUTPUT
3333
- name: update chart version
34-
uses: mikefarah/yq@v4.30.4
34+
uses: mikefarah/yq@a198f72367ce9da70b564a2cc25399de8e27bf37 # v4.35.2
3535
with:
3636
cmd: yq -i '.version = "${{ steps.inc_chart_version.outputs.NEW_CHART_VERSION }}"' charts/pipeline-controller/Chart.yaml
3737
- name: Create Pull Request
3838
id: cpr
39-
uses: peter-evans/create-pull-request@v4
39+
uses: peter-evans/create-pull-request@153407881ec5c347639a548ade7d8ad1d6740e38 # v5.0.2
4040
with:
4141
token: ${{ secrets.GHCR_TOKEN }}
4242
commit-message: |
@@ -60,22 +60,22 @@ jobs:
6060
runs-on: ubuntu-latest
6161
steps:
6262
- name: Checkout
63-
uses: actions/checkout@v3
63+
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
6464
with:
6565
repository: weaveworks/weave-gitops-enterprise
6666
token: ${{ secrets.GHCR_TOKEN }}
6767
- name: Setup Helm
68-
uses: azure/setup-helm@v3
68+
uses: azure/setup-helm@5119fcb9089d432beecbf79bb2c7915207344b78 # v3.5
6969
with:
7070
version: v3.10.1
7171
- name: Debug
7272
run: echo '${{ toJSON(github.event) }}'
7373
- name: Update pipeline-controller chart version
74-
uses: mikefarah/yq@v4.30.4
74+
uses: mikefarah/yq@a198f72367ce9da70b564a2cc25399de8e27bf37 # v4.35.2
7575
with:
7676
cmd: yq -i '(.dependencies[] | select(.name=="pipeline-controller") | .version) |= "${{ github.event.registry_package.package_version.container_metadata.tag.name }}"' charts/mccp/Chart.yaml
7777
- name: Login to GitHub Container Registry
78-
uses: docker/login-action@v2
78+
uses: docker/login-action@343f7c4344506bcbf9b4de18042ae17996df046d # v3.0.0
7979
with:
8080
registry: ghcr.io
8181
username: ${{ github.actor }}
@@ -84,7 +84,7 @@ jobs:
8484
run: cd ./charts/mccp && helm dependency update
8585
- name: Create Pull Request
8686
id: cpr
87-
uses: peter-evans/create-pull-request@v4
87+
uses: peter-evans/create-pull-request@153407881ec5c347639a548ade7d8ad1d6740e38 # v5.0.2
8888
with:
8989
token: ${{ secrets.GHCR_TOKEN }}
9090
commit-message: |

0 commit comments

Comments
 (0)