diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index c1b289c27fa..0602ae242b4 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -25,7 +25,7 @@ jobs: matrix: format: [ deb, rpm, apk ] steps: - - uses: actions/checkout@b0e28b5ac45a892f91e7d036f8200cf5ed489415 # v3 + - uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b # v3 with: fetch-depth: 0 - uses: arduino/setup-task@ca745e18916de727f841ec824ac20a615f1cddea # v1 @@ -46,7 +46,7 @@ jobs: env: DOCKER_CLI_EXPERIMENTAL: "enabled" steps: - - uses: actions/checkout@b0e28b5ac45a892f91e7d036f8200cf5ed489415 # v3 + - uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b # v3 with: fetch-depth: 0 - uses: arduino/setup-task@ca745e18916de727f841ec824ac20a615f1cddea # v1 diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 08ea19f0d68..95373f8b58f 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -15,7 +15,7 @@ jobs: contents: read steps: - - uses: actions/checkout@b0e28b5ac45a892f91e7d036f8200cf5ed489415 # v3 + - uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b # v3 - uses: github/codeql-action/init@2ca79b6fa8d3ec278944088b4aa5f46912db5d63 # v2 - uses: github/codeql-action/autobuild@2ca79b6fa8d3ec278944088b4aa5f46912db5d63 # v2 - uses: github/codeql-action/analyze@2ca79b6fa8d3ec278944088b4aa5f46912db5d63 # v2 diff --git a/.github/workflows/depsreview.yaml b/.github/workflows/depsreview.yaml index 2716756a17d..80b8a90c59b 100644 --- a/.github/workflows/depsreview.yaml +++ b/.github/workflows/depsreview.yaml @@ -8,7 +8,7 @@ jobs: dependency-review: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v3 + - uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b # v3 - uses: actions/dependency-review-action@v2 with: allow-licenses: BSD-2-Clause, BSD-3-Clause, MIT, Apache-2.0, MPL-2.0 diff --git a/.github/workflows/docs.yml b/.github/workflows/docs.yml index 594bdc17e93..a00893aae29 100644 --- a/.github/workflows/docs.yml +++ b/.github/workflows/docs.yml @@ -17,7 +17,7 @@ jobs: htmltest: runs-on: ubuntu-latest steps: - - uses: actions/checkout@b0e28b5ac45a892f91e7d036f8200cf5ed489415 # v3 + - uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b # v3 - uses: arduino/setup-task@ca745e18916de727f841ec824ac20a615f1cddea # v1 with: repo-token: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/generate.yml b/.github/workflows/generate.yml index 694b737ff06..f94cc48998e 100644 --- a/.github/workflows/generate.yml +++ b/.github/workflows/generate.yml @@ -19,7 +19,7 @@ jobs: contents: write # for stefanzweifel/git-auto-commit-action to push code in repo runs-on: ubuntu-latest steps: - - uses: actions/checkout@b0e28b5ac45a892f91e7d036f8200cf5ed489415 # v3 + - uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b # v3 with: token: ${{ secrets.GH_PAT }} - uses: actions/setup-go@84cbf8094393cdc5fe1fe1671ff2647332956b1a # v3 diff --git a/.github/workflows/gitleaks.yml b/.github/workflows/gitleaks.yml index d06b88252ef..456035e3cb7 100644 --- a/.github/workflows/gitleaks.yml +++ b/.github/workflows/gitleaks.yml @@ -13,7 +13,7 @@ jobs: gitleaks: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v1 + - uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b # v3 - uses: gitleaks/gitleaks-action@v2 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/grype.yml b/.github/workflows/grype.yml index 5ab745ddb82..ad8421dcdd6 100644 --- a/.github/workflows/grype.yml +++ b/.github/workflows/grype.yml @@ -15,7 +15,7 @@ jobs: contents: read steps: - - uses: actions/checkout@b0e28b5ac45a892f91e7d036f8200cf5ed489415 # v3 + - uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b # v3 - uses: anchore/scan-action@v3 with: path: "." diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml index dd3ce21ff9c..4efdb4dd905 100644 --- a/.github/workflows/lint.yml +++ b/.github/workflows/lint.yml @@ -20,7 +20,7 @@ jobs: - uses: actions/setup-go@84cbf8094393cdc5fe1fe1671ff2647332956b1a # v3 with: go-version: ~1.19 - - uses: actions/checkout@b0e28b5ac45a892f91e7d036f8200cf5ed489415 # v3 + - uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b # v3 - name: golangci-lint uses: golangci/golangci-lint-action@537aa1903e5d359d0b27dbc19ddd22c5087f3fbc # v3 with: