diff --git a/.github/workflows/ci-python.yml b/.github/workflows/ci-python.yml index 00438596067..a6aa76f038d 100644 --- a/.github/workflows/ci-python.yml +++ b/.github/workflows/ci-python.yml @@ -127,7 +127,7 @@ jobs: timeout-minutes: 2 - name: Setup Rust toolchain - uses: actions-rust-lang/setup-rust-toolchain@f3c84ee10bf5a86e7a5d607d487bf17d57670965 # pin v1.5.0 + uses: actions-rust-lang/setup-rust-toolchain@c7e1de28469b16b21a170a200a7a9e810bb5cdff # pin v1.6.0 if: (!inputs.style-only) && steps.cache-libparsec.outputs.cache-hit != 'true' with: # We setup the cache by hand, see below diff --git a/.github/workflows/ci-rust.yml b/.github/workflows/ci-rust.yml index c296980aeed..78b710ad9ec 100644 --- a/.github/workflows/ci-rust.yml +++ b/.github/workflows/ci-rust.yml @@ -59,7 +59,7 @@ jobs: - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # pin v4.1.1 timeout-minutes: 5 - - uses: actions-rust-lang/setup-rust-toolchain@f3c84ee10bf5a86e7a5d607d487bf17d57670965 # pin v1.5.0 + - uses: actions-rust-lang/setup-rust-toolchain@c7e1de28469b16b21a170a200a7a9e810bb5cdff # pin v1.6.0 with: # We setup the cache by hand, see below cache: false @@ -85,7 +85,7 @@ jobs: timeout-minutes: 5 # Install cargo nextest command - - uses: taiki-e/install-action@b61491983a082ef851796e8c4feac004b49da5be # pin v2.21.19 + - uses: taiki-e/install-action@d211c4be5a95cbcd52a0870dda7d63a107a58368 # pin v2.21.26 with: tool: nextest@0.9.54, wasm-pack@0.11.0, cargo-deny@0.14.3 @@ -169,7 +169,7 @@ jobs: - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # pin v4.1.1 timeout-minutes: 5 - - uses: actions-rust-lang/setup-rust-toolchain@f3c84ee10bf5a86e7a5d607d487bf17d57670965 # pin v1.5.0 + - uses: actions-rust-lang/setup-rust-toolchain@c7e1de28469b16b21a170a200a7a9e810bb5cdff # pin v1.6.0 with: # We setup the cache by hand, see below cache: false @@ -205,7 +205,7 @@ jobs: mv 'D:/a/_temp/winfsp-tests-x64.exe' 'C:/Program Files (x86)/WinFsp/bin/' # Install cargo nextest command - - uses: taiki-e/install-action@b61491983a082ef851796e8c4feac004b49da5be # pin v2.21.19 + - uses: taiki-e/install-action@d211c4be5a95cbcd52a0870dda7d63a107a58368 # pin v2.21.26 with: tool: nextest@0.9.54 diff --git a/.github/workflows/ci-web.yml b/.github/workflows/ci-web.yml index 7ec0bcac89c..4b32f315b29 100644 --- a/.github/workflows/ci-web.yml +++ b/.github/workflows/ci-web.yml @@ -90,7 +90,7 @@ jobs: timeout-minutes: 2 - name: Setup Rust toolchain - uses: actions-rust-lang/setup-rust-toolchain@f3c84ee10bf5a86e7a5d607d487bf17d57670965 # pin v1.5.0 + uses: actions-rust-lang/setup-rust-toolchain@c7e1de28469b16b21a170a200a7a9e810bb5cdff # pin v1.6.0 if: steps.cache-libparsec.outputs.cache-hit != 'true' with: target: wasm32-unknown-unknown @@ -110,7 +110,7 @@ jobs: timeout-minutes: 5 # Install wasm-pack command - - uses: taiki-e/install-action@b61491983a082ef851796e8c4feac004b49da5be # pin v2.21.19 + - uses: taiki-e/install-action@d211c4be5a95cbcd52a0870dda7d63a107a58368 # pin v2.21.26 with: tool: wasm-pack@${{ env.wasm-pack-version }} diff --git a/.github/workflows/cspell.yml b/.github/workflows/cspell.yml index cb9d8a59ebc..710af0d0e1b 100644 --- a/.github/workflows/cspell.yml +++ b/.github/workflows/cspell.yml @@ -74,7 +74,7 @@ jobs: - name: Check spelling in the repository id: cspell - uses: streetsidesoftware/cspell-action@52cba17693dc12d7d8f521631037008a17c93e53 # pin v5.0.0 + uses: streetsidesoftware/cspell-action@d4c3df16cdd0faebccb1711178a8a490966f61b9 # pin v5.0.1 with: config: .cspell/cspell.config.yml # Only check for changed files on a PR diff --git a/.github/workflows/docker-server.yml b/.github/workflows/docker-server.yml index a22126521b1..ae275bf8633 100644 --- a/.github/workflows/docker-server.yml +++ b/.github/workflows/docker-server.yml @@ -49,7 +49,7 @@ jobs: sed -n 's/^.*Tool.Parsec: "\(.*\)",$/current=\1/p' misc/version_updater.py | tee $GITHUB_OUTPUT - name: Generate build metadata - uses: docker/metadata-action@96383f45573cb7f253c731d3b3ab81c87ef81934 # v5.0.0 + uses: docker/metadata-action@e6428a5c4e294a61438ed7f43155db912025b6b3 # v5.2.0 id: metadata with: images: diff --git a/.github/workflows/docker-testbed.yml b/.github/workflows/docker-testbed.yml index 36da588bb18..889efa1aebd 100644 --- a/.github/workflows/docker-testbed.yml +++ b/.github/workflows/docker-testbed.yml @@ -62,7 +62,7 @@ jobs: timeout-minutes: 1 - name: Generate build metadata - uses: docker/metadata-action@96383f45573cb7f253c731d3b3ab81c87ef81934 # v5.0.0 + uses: docker/metadata-action@e6428a5c4e294a61438ed7f43155db912025b6b3 # v5.2.0 id: metadata with: images: diff --git a/.github/workflows/package-ionic-app.yml b/.github/workflows/package-ionic-app.yml index 37ad3c889ff..7d1c01a9ef9 100644 --- a/.github/workflows/package-ionic-app.yml +++ b/.github/workflows/package-ionic-app.yml @@ -41,7 +41,7 @@ jobs: working-directory: client # Install syft - - uses: taiki-e/install-action@b61491983a082ef851796e8c4feac004b49da5be # pin v2.21.19 + - uses: taiki-e/install-action@d211c4be5a95cbcd52a0870dda7d63a107a58368 # pin v2.21.26 with: tool: syft@0.84.0, wasm-pack@${{ env.wasm-pack-version }} @@ -118,7 +118,7 @@ jobs: timeout-minutes: 5 # Install syft - - uses: taiki-e/install-action@b61491983a082ef851796e8c4feac004b49da5be # pin v2.21.19 + - uses: taiki-e/install-action@d211c4be5a95cbcd52a0870dda7d63a107a58368 # pin v2.21.26 with: tool: syft@0.84.0 diff --git a/.github/workflows/package-server.yml b/.github/workflows/package-server.yml index 4524832bd60..8b3a0a4fad5 100644 --- a/.github/workflows/package-server.yml +++ b/.github/workflows/package-server.yml @@ -139,7 +139,7 @@ jobs: run: python server/packaging/wheel/wheel_it.py ./server --output dist --skip-wheel # Install syft - - uses: taiki-e/install-action@b61491983a082ef851796e8c4feac004b49da5be # pin v2.21.19 + - uses: taiki-e/install-action@d211c4be5a95cbcd52a0870dda7d63a107a58368 # pin v2.21.26 with: tool: syft@0.84.0 diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 1d1eccc5c23..2b333870ea3 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -92,7 +92,7 @@ jobs: timeout-minutes: 2 - name: Publish wheel on PyPI - uses: pypa/gh-action-pypi-publish@b7f401de30cb6434a1e19f805ff006643653240e # pin v1.8.10 + uses: pypa/gh-action-pypi-publish@2f6f737ca5f74c637829c0f5c3acd0e29ea5e8bf # pin v1.8.11 with: user: __token__ password: ${{ secrets.PYPI_CREDENTIALS }}