Skip to content

Commit 9e887c3

Browse files
authored
ci: pin actions to commit-hash (#390)
1 parent 887dc6b commit 9e887c3

File tree

3 files changed

+11
-11
lines changed

3 files changed

+11
-11
lines changed

.github/workflows/benchmarks.yml

+3-3
Original file line numberDiff line numberDiff line change
@@ -25,10 +25,10 @@ jobs:
2525
contents: write
2626
steps:
2727
- name: Check out repo
28-
uses: actions/checkout@v4
28+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
2929

3030
- name: Setup Node
31-
uses: actions/setup-node@v4
31+
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
3232
with:
3333
check-latest: true
3434
node-version: 20
@@ -45,7 +45,7 @@ jobs:
4545
node ./benchmark compare -u
4646
4747
- name: Commit and push updated results
48-
uses: github-actions-x/[email protected]
48+
uses: github-actions-x/commit@722d56b8968bf00ced78407bbe2ead81062d8baa # v2.9
4949
with:
5050
github-token: ${{ secrets.GITHUB_TOKEN }}
5151
push-branch: 'main'

.github/workflows/ci.yml

+5-5
Original file line numberDiff line numberDiff line change
@@ -19,12 +19,12 @@ jobs:
1919
contents: read
2020
steps:
2121
- name: Check out repo
22-
uses: actions/checkout@v4
22+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
2323
with:
2424
persist-credentials: false
2525

2626
- name: Dependency review
27-
uses: actions/dependency-review-action@v4
27+
uses: actions/dependency-review-action@ce3cf9537a52e8119d91fd484ab5b8a807627bf8 # v4.6.0
2828

2929
test:
3030
name: Test
@@ -36,12 +36,12 @@ jobs:
3636
node-version: [20, 22]
3737
steps:
3838
- name: Check out repo
39-
uses: actions/checkout@v4
39+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
4040
with:
4141
persist-credentials: false
4242

4343
- name: Setup Node ${{ matrix.node-version }}
44-
uses: actions/setup-node@v4
44+
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
4545
with:
4646
check-latest: true
4747
node-version: ${{ matrix.node-version }}
@@ -63,7 +63,7 @@ jobs:
6363
contents: write
6464
runs-on: ubuntu-latest
6565
steps:
66-
- uses: fastify/github-action-merge-dependabot@v3
66+
- uses: fastify/github-action-merge-dependabot@e820d631adb1d8ab16c3b93e5afe713450884a4a # v3.11.1
6767
with:
6868
github-token: ${{ secrets.GITHUB_TOKEN }}
6969
target: minor

.github/workflows/metrics.yml

+3-3
Original file line numberDiff line numberDiff line change
@@ -22,10 +22,10 @@ jobs:
2222
contents: write
2323
steps:
2424
- name: Check out repo
25-
uses: actions/checkout@v4
25+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
2626

2727
- name: Setup Node
28-
uses: actions/setup-node@v4
28+
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
2929
with:
3030
check-latest: true
3131
node-version: 20
@@ -39,7 +39,7 @@ jobs:
3939
npm run metrics:summary
4040
4141
- name: Commit and push updated results
42-
uses: github-actions-x/[email protected]
42+
uses: github-actions-x/commit@722d56b8968bf00ced78407bbe2ead81062d8baa # v2.9
4343
with:
4444
github-token: ${{ secrets.GITHUB_TOKEN }}
4545
push-branch: 'main'

0 commit comments

Comments
 (0)