Skip to content

Commit 53ee84d

Browse files
authored
Pin actions to commit (microsoft#2797)
1 parent 33dacfa commit 53ee84d

File tree

5 files changed

+36
-36
lines changed

5 files changed

+36
-36
lines changed

.github/workflows/build.yaml

+27-27
Original file line numberDiff line numberDiff line change
@@ -35,12 +35,12 @@ jobs:
3535

3636
steps:
3737
- name: Checkout
38-
uses: actions/checkout@v4
38+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
3939
with:
4040
fetch-depth: 0
4141

4242
- name: Setup .NET
43-
uses: actions/setup-dotnet@v4
43+
uses: actions/setup-dotnet@3951f0dfe7a07e2313ec93c75700083e2005cbab # v4.3.0
4444
with:
4545
global-json-file: global.json
4646

@@ -60,15 +60,15 @@ jobs:
6060
run: dotnet format --verify-no-changes
6161

6262
- name: Upload module
63-
uses: actions/upload-artifact@v4
63+
uses: actions/upload-artifact@4cec3d8aa04e39d1a68397de0c4cd6fb9dce8ec1 # v4.6.1
6464
with:
6565
name: Module
6666
path: ./out/modules/PSRule/*
6767
retention-days: 3
6868
if-no-files-found: error
6969

7070
- name: Upload PSRule Results
71-
uses: actions/upload-artifact@v4
71+
uses: actions/upload-artifact@4cec3d8aa04e39d1a68397de0c4cd6fb9dce8ec1 # v4.6.1
7272
if: always()
7373
with:
7474
name: Results-PSRule
@@ -110,10 +110,10 @@ jobs:
110110

111111
steps:
112112
- name: Checkout
113-
uses: actions/checkout@v4
113+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
114114

115115
- name: Setup .NET
116-
uses: actions/setup-dotnet@v4
116+
uses: actions/setup-dotnet@3951f0dfe7a07e2313ec93c75700083e2005cbab # v4.3.0
117117
with:
118118
global-json-file: global.json
119119

@@ -154,17 +154,17 @@ jobs:
154154
contents: read
155155
steps:
156156
- name: Checkout
157-
uses: actions/checkout@v4
157+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
158158
with:
159159
fetch-depth: 0
160160

161161
- name: Setup node.js
162-
uses: actions/setup-node@v4
162+
uses: actions/setup-node@1d0ff469b7ec7b3cb9d8673fde0c81c44821de2a # v4.2.0
163163
with:
164164
node-version: 20
165165

166166
- name: Setup .NET
167-
uses: actions/setup-dotnet@v4
167+
uses: actions/setup-dotnet@3951f0dfe7a07e2313ec93c75700083e2005cbab # v4.3.0
168168
with:
169169
global-json-file: global.json
170170

@@ -183,7 +183,7 @@ jobs:
183183
npm run package -- 0.0.1
184184
185185
- name: Upload extension
186-
uses: actions/upload-artifact@v4
186+
uses: actions/upload-artifact@4cec3d8aa04e39d1a68397de0c4cd6fb9dce8ec1 # v4.6.1
187187
with:
188188
name: Extension
189189
path: out/package/vscode-ps-rule-*.vsix
@@ -207,15 +207,15 @@ jobs:
207207

208208
steps:
209209
- name: Checkout
210-
uses: actions/checkout@v4
210+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
211211

212212
- name: Setup node.js
213-
uses: actions/setup-node@v4
213+
uses: actions/setup-node@1d0ff469b7ec7b3cb9d8673fde0c81c44821de2a # v4.2.0
214214
with:
215215
node-version: 20
216216

217217
- name: Setup .NET
218-
uses: actions/setup-dotnet@v4
218+
uses: actions/setup-dotnet@3951f0dfe7a07e2313ec93c75700083e2005cbab # v4.3.0
219219
with:
220220
global-json-file: global.json
221221

@@ -245,12 +245,12 @@ jobs:
245245

246246
steps:
247247
- name: Checkout
248-
uses: actions/checkout@v4
248+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
249249
with:
250250
fetch-depth: 0
251251

252252
- name: Setup Python
253-
uses: actions/setup-python@v5
253+
uses: actions/setup-python@42375524e23c412d93fb67b49958b491fce71c38 # v5.4.0
254254
with:
255255
python-version: '3.11'
256256
architecture: 'x64'
@@ -277,7 +277,7 @@ jobs:
277277
security-events: write
278278
steps:
279279
- name: Checkout
280-
uses: actions/checkout@v4
280+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
281281

282282
- name: Run PSRule analysis
283283
uses: microsoft/[email protected]
@@ -289,13 +289,13 @@ jobs:
289289
option: ps-rule-ci.yaml
290290

291291
- name: Upload results to security tab
292-
uses: github/codeql-action/upload-sarif@v3
292+
uses: github/codeql-action/upload-sarif@b56ba49b26e50535fa1e7f7db0f4f7b4bf65d80d # v3.28.10
293293
if: always()
294294
with:
295295
sarif_file: reports/ps-rule-results.sarif
296296

297297
- name: Upload results
298-
uses: actions/upload-artifact@v4
298+
uses: actions/upload-artifact@4cec3d8aa04e39d1a68397de0c4cd6fb9dce8ec1 # v4.6.1
299299
if: always()
300300
with:
301301
name: PSRule-Sarif
@@ -312,21 +312,21 @@ jobs:
312312
security-events: write
313313
steps:
314314
- name: Checkout
315-
uses: actions/checkout@v4
315+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
316316

317317
- name: Run DevSkim scanner
318-
uses: microsoft/DevSkim-Action@v1
318+
uses: microsoft/DevSkim-Action@a6b6966a33b497cd3ae2ebc406edf8f4cc2feec6 # v1.0.15
319319
with:
320320
directory-to-scan: .
321321

322322
- name: Upload results to security tab
323-
uses: github/codeql-action/upload-sarif@v3
323+
uses: github/codeql-action/upload-sarif@b56ba49b26e50535fa1e7f7db0f4f7b4bf65d80d # v3.28.10
324324
if: always()
325325
with:
326326
sarif_file: devskim-results.sarif
327327

328328
- name: Upload results
329-
uses: actions/upload-artifact@v4
329+
uses: actions/upload-artifact@4cec3d8aa04e39d1a68397de0c4cd6fb9dce8ec1 # v4.6.1
330330
if: always()
331331
with:
332332
name: DevSkim-Sarif
@@ -343,22 +343,22 @@ jobs:
343343
security-events: write
344344
steps:
345345
- name: Checkout
346-
uses: actions/checkout@v4
346+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
347347

348348
- name: Initialize CodeQL
349-
uses: github/codeql-action/init@v3
349+
uses: github/codeql-action/init@b56ba49b26e50535fa1e7f7db0f4f7b4bf65d80d # v3.28.10
350350
with:
351351
languages: 'csharp'
352352

353353
- name: Autobuild
354-
uses: github/codeql-action/autobuild@v3
354+
uses: github/codeql-action/autobuild@b56ba49b26e50535fa1e7f7db0f4f7b4bf65d80d # v3.28.10
355355

356356
- name: Perform CodeQL Analysis
357-
uses: github/codeql-action/analyze@v3
357+
uses: github/codeql-action/analyze@b56ba49b26e50535fa1e7f7db0f4f7b4bf65d80d # v3.28.10
358358
id: codeql-analyze
359359

360360
- name: Upload results
361-
uses: actions/upload-artifact@v4
361+
uses: actions/upload-artifact@4cec3d8aa04e39d1a68397de0c4cd6fb9dce8ec1 # v4.6.1
362362
if: always()
363363
with:
364364
name: CodeQL-Sarif

.github/workflows/dependencies.yaml

+1-1
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ jobs:
2626
pull-requests: write
2727
steps:
2828
- name: Checkout
29-
uses: actions/checkout@v4
29+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
3030
with:
3131
fetch-depth: 0
3232

.github/workflows/docs.yaml

+6-6
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ jobs:
2222
contents: write
2323
steps:
2424
- name: Checkout
25-
uses: actions/checkout@v4
25+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
2626
with:
2727
fetch-depth: 0
2828

@@ -32,7 +32,7 @@ jobs:
3232
git config user.email '41898282+github-actions[bot]@users.noreply.github.com'
3333
3434
- name: Setup Python
35-
uses: actions/setup-python@v5
35+
uses: actions/setup-python@42375524e23c412d93fb67b49958b491fce71c38 # v5.4.0
3636
with:
3737
python-version: '3.11'
3838
architecture: 'x64'
@@ -64,18 +64,18 @@ jobs:
6464
id-token: write
6565
steps:
6666
- name: Checkout
67-
uses: actions/checkout@v4
67+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
6868
with:
6969
ref: refs/heads/gh-pages
7070

7171
- name: Setup Pages
72-
uses: actions/configure-pages@v5
72+
uses: actions/configure-pages@983d7736d9b0ae728b81ab479565c72886d7745b # v5.0.0
7373

7474
- name: Upload artifact
75-
uses: actions/upload-pages-artifact@v3
75+
uses: actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa # v3.0.1
7676
with:
7777
path: '.'
7878

7979
- name: Deploy to GitHub Pages
8080
id: deployment
81-
uses: actions/deploy-pages@v4
81+
uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e # v4.0.5

.github/workflows/first-interaction.yaml

+1-1
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ jobs:
1919
issues: write
2020
pull-requests: write
2121
steps:
22-
- uses: actions/first-interaction@v1
22+
- uses: actions/first-interaction@34f15e814fe48ac9312ccf29db4e74fa767cbab7 # v1.3.0
2323
with:
2424
repo-token: ${{ secrets.GITHUB_TOKEN }}
2525
issue-message: 'Thanks for raising your first issue, the team appreciates the time you have taken 😉'

.github/workflows/stale.yaml

+1-1
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ jobs:
2121
permissions:
2222
issues: write
2323
steps:
24-
- uses: actions/stale@v9
24+
- uses: actions/stale@5bef64f19d7facfb25b37b414482c7164d639639 # v9.1.0
2525
with:
2626
stale-issue-message: >
2727
This issue has been automatically marked as stale because it has not had

0 commit comments

Comments
 (0)