diff --git a/.github/workflows/automerge.yml b/.github/workflows/automerge.yml index c4165ba31..6d079b38a 100644 --- a/.github/workflows/automerge.yml +++ b/.github/workflows/automerge.yml @@ -23,7 +23,7 @@ jobs: runs-on: ubuntu-latest steps: - name: automerge - uses: pascalgn/automerge-action@v0.12.0 + uses: pascalgn/automerge-action@c9bd1823770819dc8fb8a5db2d11a3a95fbe9b07 # tag=v0.12.0 env: # Allows this merge to trigger other actions GITHUB_TOKEN: "${{ secrets.GITHUB_TOKEN }}" diff --git a/.github/workflows/pr-auditor.yml b/.github/workflows/pr-auditor.yml index 3edc2741b..e455376b7 100644 --- a/.github/workflows/pr-auditor.yml +++ b/.github/workflows/pr-auditor.yml @@ -7,9 +7,9 @@ jobs: run: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v2 + - uses: actions/checkout@ec3a7ce113134d7a93b817d10a8272cb61118579 # tag=v2 with: { repository: 'sourcegraph/sourcegraph' } - - uses: actions/setup-go@v2 + - uses: actions/setup-go@bfdd3570ce990073878bf10f6b2d79082de49492 # tag=v2 with: { go-version: '1.17' } - run: ./dev/pr-auditor/check-pr.sh diff --git a/.github/workflows/update-tags.yml b/.github/workflows/update-tags.yml index 09d3b7f6a..f0453f74b 100644 --- a/.github/workflows/update-tags.yml +++ b/.github/workflows/update-tags.yml @@ -11,8 +11,8 @@ jobs: dispatch: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v2 - - uses: actions/setup-go@v2 + - uses: actions/checkout@ec3a7ce113134d7a93b817d10a8272cb61118579 # tag=v2 + - uses: actions/setup-go@bfdd3570ce990073878bf10f6b2d79082de49492 # tag=v2 with: go-version: '^1.14' @@ -20,7 +20,7 @@ jobs: - name: Pin tags to ${{ github.event.inputs.semver }} run: tools/update-docker-tags.sh "${{ github.event.inputs.semver }}" - name: Open pull request - uses: peter-evans/create-pull-request@v3 + uses: peter-evans/create-pull-request@18f7dc018cc2cd597073088f7c7591b9d1c02672 # tag=v3 with: token: ${{ secrets.GITHUB_TOKEN }} base: ${{ github.event.inputs.branch }}