Skip to content

Commit 660f1db

Browse files
chore(ci): harden github actions
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
1 parent d28e199 commit 660f1db

13 files changed

+24
-24
lines changed

.github/workflows/checks.codeql.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -111,7 +111,7 @@ jobs:
111111
with:
112112
merge-multiple: true
113113
- name: "Analysis: Build"
114-
uses: gradle/actions/setup-gradle@v3.1.0
114+
uses: gradle/actions/setup-gradle@417ae3ccd767c252f5661f1ace9f835f9654f2b5 # v3.1.0
115115
continue-on-error: true
116116
env:
117117
CI: true

.github/workflows/checks.detekt.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -91,7 +91,7 @@ jobs:
9191
- name: "Setup: Git History"
9292
run: git fetch --unshallow || exit 0
9393
- name: "Analysis: Detekt"
94-
uses: gradle/actions/setup-gradle@v3.1.0
94+
uses: gradle/actions/setup-gradle@417ae3ccd767c252f5661f1ace9f835f9654f2b5 # v3.1.0
9595
continue-on-error: true
9696
env:
9797
CI: true

.github/workflows/checks.qodana.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -91,7 +91,7 @@ jobs:
9191
with:
9292
merge-multiple: true
9393
- name: "Analysis: Build"
94-
uses: gradle/actions/setup-gradle@v3.1.0
94+
uses: gradle/actions/setup-gradle@417ae3ccd767c252f5661f1ace9f835f9654f2b5 # v3.1.0
9595
continue-on-error: true
9696
with:
9797
cache-read-only: true

.github/workflows/checks.sonar.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -109,7 +109,7 @@ jobs:
109109
- name: "Setup: Git History"
110110
run: git fetch --unshallow || exit 0
111111
- name: "Build: Verify Coverage"
112-
uses: gradle/actions/setup-gradle@v3.1.0
112+
uses: gradle/actions/setup-gradle@417ae3ccd767c252f5661f1ace9f835f9654f2b5 # v3.1.0
113113
continue-on-error: true
114114
env:
115115
CI: true
@@ -124,7 +124,7 @@ jobs:
124124
-x nativeCompile
125125
-x nativeOptimizedCompile
126126
- name: "Analysis: Sonar"
127-
uses: gradle/actions/setup-gradle@v3.1.0
127+
uses: gradle/actions/setup-gradle@417ae3ccd767c252f5661f1ace9f835f9654f2b5 # v3.1.0
128128
continue-on-error: true
129129
env:
130130
CI: true

.github/workflows/job.bench.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -93,7 +93,7 @@ jobs:
9393
- name: "Setup: Yarn"
9494
run: yarn
9595
- name: "Run Benchmarks"
96-
uses: gradle/actions/setup-gradle@v3.1.0
96+
uses: gradle/actions/setup-gradle@417ae3ccd767c252f5661f1ace9f835f9654f2b5 # v3.1.0
9797
id: gradlebench
9898
continue-on-error: ${{ matrix.experimental }}
9999
env:

.github/workflows/job.build.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -246,7 +246,7 @@ jobs:
246246
export_environment_variables: true
247247
cleanup_credentials: true
248248
- name: "🛠️ Build"
249-
uses: gradle/actions/setup-gradle@v3.1.0
249+
uses: gradle/actions/setup-gradle@417ae3ccd767c252f5661f1ace9f835f9654f2b5 # v3.1.0
250250
id: gradlebuild
251251
continue-on-error: ${{ matrix.mode == 'labs' }}
252252
env:

.github/workflows/job.cli.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -207,7 +207,7 @@ jobs:
207207
with:
208208
merge-multiple: true
209209
- name: "Build: CLI (Native/Debug)"
210-
uses: gradle/actions/setup-gradle@v3.1.0
210+
uses: gradle/actions/setup-gradle@417ae3ccd767c252f5661f1ace9f835f9654f2b5 # v3.1.0
211211
env:
212212
CI: true
213213
BUILDLESS_APIKEY: ${{ secrets.BUILDLESS_APIKEY }}
@@ -380,7 +380,7 @@ jobs:
380380
with:
381381
merge-multiple: true
382382
- name: "Build: CLI (Native/Release)"
383-
uses: gradle/actions/setup-gradle@v3.1.0
383+
uses: gradle/actions/setup-gradle@417ae3ccd767c252f5661f1ace9f835f9654f2b5 # v3.1.0
384384
env:
385385
CI: true
386386
BUILDLESS_APIKEY: ${{ secrets.BUILDLESS_APIKEY }}

.github/workflows/job.containers.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -238,7 +238,7 @@ jobs:
238238
## -- Samples -- ##
239239
- name: "Build/Push: '${{ matrix.project }}' (JVM)"
240240
continue-on-error: ${{ fromJson(matrix.labs) }}
241-
uses: gradle/actions/setup-gradle@v3.1.0
241+
uses: gradle/actions/setup-gradle@417ae3ccd767c252f5661f1ace9f835f9654f2b5 # v3.1.0
242242
with:
243243
arguments: |
244244
--no-daemon
@@ -360,7 +360,7 @@ jobs:
360360

361361
## -- Samples -- ##
362362
- name: "Build/Push: '${{ matrix.project }}' (Native)"
363-
uses: gradle/actions/setup-gradle@v3.1.0
363+
uses: gradle/actions/setup-gradle@417ae3ccd767c252f5661f1ace9f835f9654f2b5 # v3.1.0
364364
continue-on-error: true
365365
with:
366366
arguments: |

.github/workflows/job.site.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -79,7 +79,7 @@ jobs:
7979
run: |
8080
make docs reports CI=yes JVM=21
8181
- name: "Build: Site"
82-
uses: gradle/actions/setup-gradle@v3.1.0
82+
uses: gradle/actions/setup-gradle@417ae3ccd767c252f5661f1ace9f835f9654f2b5 # v3.1.0
8383
env:
8484
CI: true
8585
with:

.github/workflows/job.test.yml

+5-5
Original file line numberDiff line numberDiff line change
@@ -233,7 +233,7 @@ jobs:
233233
with:
234234
merge-multiple: true
235235
- name: "Testsuite"
236-
uses: gradle/actions/setup-gradle@v3.1.0
236+
uses: gradle/actions/setup-gradle@417ae3ccd767c252f5661f1ace9f835f9654f2b5 # v3.1.0
237237
env:
238238
CI: true
239239
BUILDLESS_APIKEY: ${{ secrets.BUILDLESS_APIKEY }}
@@ -277,7 +277,7 @@ jobs:
277277
-PbuildDocs=false
278278
-PbuildDocsSite=false
279279
- name: "Analysis: Sonar"
280-
uses: gradle/actions/setup-gradle@v3.1.0
280+
uses: gradle/actions/setup-gradle@417ae3ccd767c252f5661f1ace9f835f9654f2b5 # v3.1.0
281281
continue-on-error: true
282282
env:
283283
CI: true
@@ -319,7 +319,7 @@ jobs:
319319
-PbuildDocs=false
320320
-PbuildDocsSite=false
321321
- name: "Analysis: Sonar"
322-
uses: gradle/actions/setup-gradle@v3.1.0
322+
uses: gradle/actions/setup-gradle@417ae3ccd767c252f5661f1ace9f835f9654f2b5 # v3.1.0
323323
continue-on-error: true
324324
env:
325325
CI: true
@@ -362,7 +362,7 @@ jobs:
362362
-PbuildDocs=false
363363
-PbuildDocsSite=false
364364
- name: "Runtime Self-tests (JVM)"
365-
uses: gradle/actions/setup-gradle@v3.1.0
365+
uses: gradle/actions/setup-gradle@417ae3ccd767c252f5661f1ace9f835f9654f2b5 # v3.1.0
366366
continue-on-error: true
367367
env:
368368
CI: true
@@ -532,7 +532,7 @@ jobs:
532532
with:
533533
merge-multiple: true
534534
- name: "Run Tests (Native)"
535-
uses: gradle/actions/setup-gradle@v3.1.0
535+
uses: gradle/actions/setup-gradle@417ae3ccd767c252f5661f1ace9f835f9654f2b5 # v3.1.0
536536
continue-on-error: true
537537
env:
538538
CI: true

.github/workflows/on.pr.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -113,7 +113,7 @@ jobs:
113113
submodules: true
114114
persist-credentials: false
115115
- name: "Setup: Buildless"
116-
uses: buildless/setup@v1.0.2
116+
uses: buildless/setup@30e82389418c7f17046606183bc4c78b2c8913e0 # v1.0.2
117117
- name: "Setup: GraalVM (Java 21)"
118118
uses: graalvm/setup-graalvm@2a93b69fdf86ac5a078a98c1a707744632e1da94 # v1.1.5
119119
with:
@@ -131,7 +131,7 @@ jobs:
131131
elide-framework-v1-
132132
elide-framework-
133133
- name: "Check: Library ABI"
134-
uses: gradle/actions/setup-gradle@v3.1.0
134+
uses: gradle/actions/setup-gradle@417ae3ccd767c252f5661f1ace9f835f9654f2b5 # v3.1.0
135135
id: abicheck
136136
continue-on-error: ${{ contains(github.event.pull_request.labels.*.name, 'ci:api-check-bypass') }}
137137
env:

.github/workflows/on.scheduled.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -160,7 +160,7 @@ jobs:
160160
export_environment_variables: true
161161
cleanup_credentials: true
162162
- name: "🛠️ Build"
163-
uses: gradle/actions/setup-gradle@v3.1.0
163+
uses: gradle/actions/setup-gradle@417ae3ccd767c252f5661f1ace9f835f9654f2b5 # v3.1.0
164164
id: gradlebuild
165165
continue-on-error: ${{ matrix.mode == 'labs' }}
166166
env:

.github/workflows/publish.maven.yml

+4-4
Original file line numberDiff line numberDiff line change
@@ -191,7 +191,7 @@ jobs:
191191
echo "APP_VERSION=$(cat .version)" >> $GITHUB_ENV;
192192
echo "Releasing version $APP_VERSION"
193193
- name: "Publish: Conventions"
194-
uses: gradle/actions/setup-gradle@v3.1.0
194+
uses: gradle/actions/setup-gradle@417ae3ccd767c252f5661f1ace9f835f9654f2b5 # v3.1.0
195195
if: ${{ inputs.conventions }}
196196
with:
197197
arguments: |
@@ -208,7 +208,7 @@ jobs:
208208
-x test
209209
:conventions:publish
210210
- name: "Publish: Substrate"
211-
uses: gradle/actions/setup-gradle@v3.1.0
211+
uses: gradle/actions/setup-gradle@417ae3ccd767c252f5661f1ace9f835f9654f2b5 # v3.1.0
212212
if: ${{ inputs.substrate }}
213213
with:
214214
arguments: |
@@ -225,7 +225,7 @@ jobs:
225225
-x test
226226
:substrate:publish
227227
- name: "Publish: Processor"
228-
uses: gradle/actions/setup-gradle@v3.1.0
228+
uses: gradle/actions/setup-gradle@417ae3ccd767c252f5661f1ace9f835f9654f2b5 # v3.1.0
229229
if: ${{ inputs.processor }}
230230
with:
231231
arguments: |
@@ -242,7 +242,7 @@ jobs:
242242
-x test
243243
:tools:processor:publish
244244
- name: "Publish: Packages"
245-
uses: gradle/actions/setup-gradle@v3.1.0
245+
uses: gradle/actions/setup-gradle@417ae3ccd767c252f5661f1ace9f835f9654f2b5 # v3.1.0
246246
if: ${{ inputs.packages }}
247247
with:
248248
arguments: |

0 commit comments

Comments
 (0)