Skip to content

Commit 6948784

Browse files
authored
Merge branch 'main' into dependabot/pip/pipenv-94905602c4
2 parents d75b88a + f884d28 commit 6948784

File tree

8 files changed

+29
-29
lines changed

8 files changed

+29
-29
lines changed

.github/workflows/cd.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -54,7 +54,7 @@ jobs:
5454
needs: functional-tests
5555
steps:
5656
- name: Login to GitHub Container Registry
57-
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1
57+
uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef
5858
with:
5959
registry: ghcr.io
6060
username: ${{ github.repository_owner }}
@@ -69,7 +69,7 @@ jobs:
6969
docker push ghcr.io/repository-service-tuf/repository-service-tuf-api:latest
7070
7171
- name: Publish GitHub Release
72-
uses: softprops/action-gh-release@72f2c25fcb47643c292f7107632f7a47c1df5cd8
72+
uses: softprops/action-gh-release@5be0e66d93ac7ed76da52eca8bb058f665c3a5fe
7373
with:
7474
name: ${{ github.ref_name }}
7575
tag_name: ${{ github.ref }}

.github/workflows/ci.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -15,8 +15,8 @@ jobs:
1515
python-versions: [ "3.13" ]
1616

1717
steps:
18-
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
19-
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065
18+
- uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3
19+
- uses: actions/setup-python@e797f83bcb11b83ae66e0230d6156d7c80228e7c
2020
with:
2121
python-version: ${{ matrix.python-versions }}
2222

@@ -27,7 +27,7 @@ jobs:
2727
run: tox -r
2828

2929
- name: Codecov
30-
uses: codecov/codecov-action@fdcc8476540edceab3de004e990f80d881c6cc00
30+
uses: codecov/codecov-action@5a1091511ad55cbe89839c7260b706298ca349f7
3131
with:
3232
files: coverage.xml
3333
fail_ci_if_error: false

.github/workflows/functional-tests.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -57,17 +57,17 @@ jobs:
5757

5858
steps:
5959
- name: Checkout RSTUF API source code
60-
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
60+
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3
6161

6262
- name: Checkout RSTUF Umbrella (FT)
63-
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
63+
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3
6464
with:
6565
repository: repository-service-tuf/repository-service-tuf
6666
path: rstuf-umbrella
6767
ref: ${{ inputs.umbrella_branch }}
6868

6969
- name: Deploy RSTUF with API container from source code
70-
uses: isbang/compose-action@40041ff1b97dbf152cd2361138c2b03fa29139df
70+
uses: isbang/compose-action@3846bcd61da338e9eaaf83e7ed0234a12b099b72
7171
with:
7272
compose-file: ${{ inputs.docker_compose }}
7373
env:
@@ -86,17 +86,17 @@ jobs:
8686

8787
steps:
8888
- name: Checkout RSTUF API source code
89-
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
89+
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3
9090

9191
- name: Checkout RSTUF Umbrella (FT)
92-
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
92+
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3
9393
with:
9494
repository: repository-service-tuf/repository-service-tuf
9595
path: rstuf-umbrella
9696
ref: ${{ inputs.umbrella_branch }}
9797

9898
- name: Deploy RSTUF with API container from source code
99-
uses: isbang/compose-action@40041ff1b97dbf152cd2361138c2b03fa29139df
99+
uses: isbang/compose-action@3846bcd61da338e9eaaf83e7ed0234a12b099b72
100100
with:
101101
compose-file: ${{ inputs.docker_compose }}
102102
env:

.github/workflows/publish_container.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -22,24 +22,24 @@ jobs:
2222

2323
steps:
2424
- name: Checkout release tag
25-
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
25+
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3
2626
with:
2727
fetch-depth: 0
2828
ref: ${{ inputs.image_version }}
2929

3030
- name: Set default Python version
31-
uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065
31+
uses: actions/setup-python@e797f83bcb11b83ae66e0230d6156d7c80228e7c
3232
with:
3333
python-version: '3.13'
3434

3535
- name: Set up QEMU
36-
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392
36+
uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130
3737

3838
- name: Set up Docker Buildx
3939
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435
4040

4141
- name: Login to GitHub Container Registry
42-
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1
42+
uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef
4343
with:
4444
registry: ghcr.io
4545
username: ${{ github.repository_owner }}

.github/workflows/publish_docker_dev.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -20,19 +20,19 @@ jobs:
2020
runs-on: ubuntu-latest
2121

2222
steps:
23-
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
24-
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065
23+
- uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3
24+
- uses: actions/setup-python@e797f83bcb11b83ae66e0230d6156d7c80228e7c
2525
with:
2626
python-version: '3.13'
2727

2828
- name: Set up QEMU
29-
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392
29+
uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130
3030

3131
- name: Set up Docker Buildx
3232
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435
3333

3434
- name: Login to GitHub Container Registry
35-
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1
35+
uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef
3636
with:
3737
registry: ghcr.io
3838
username: ${{ github.repository_owner }}

.github/workflows/scorecard.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -32,12 +32,12 @@ jobs:
3232

3333
steps:
3434
- name: "Checkout code"
35-
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
35+
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6.0.0
3636
with:
3737
persist-credentials: false
3838

3939
- name: "Run analysis"
40-
uses: ossf/scorecard-action@05b42c624433fc40578a4040d5cf5e36ddca8cde # v2.4.2
40+
uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3
4141
with:
4242
results_file: results.sarif
4343
results_format: sarif
@@ -59,7 +59,7 @@ jobs:
5959
# Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
6060
# format to the repository Actions tab.
6161
- name: "Upload artifact"
62-
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
62+
uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5.0.0
6363
with:
6464
name: SARIF file
6565
path: results.sarif
@@ -68,6 +68,6 @@ jobs:
6868
# Upload the results to GitHub's code scanning dashboard (optional).
6969
# Commenting out will disable upload of results to your repo's Code Scanning dashboard
7070
- name: "Upload to code-scanning"
71-
uses: github/codeql-action/upload-sarif@96f518a34f7a870018057716cc4d7a5c014bd61c # v3.29.10
71+
uses: github/codeql-action/upload-sarif@fdbfb4d2750291e159f0156def62b853c2798ca2 # v4.31.5
7272
with:
7373
sarif_file: results.sarif

.github/workflows/test_docker_build.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -9,13 +9,13 @@ jobs:
99
runs-on: ubuntu-latest
1010

1111
steps:
12-
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
13-
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065
12+
- uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3
13+
- uses: actions/setup-python@e797f83bcb11b83ae66e0230d6156d7c80228e7c
1414
with:
1515
python-version: '3.13'
1616

1717
- name: Set up QEMU
18-
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392
18+
uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130
1919

2020
- name: Set up Docker Buildx
2121
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435

.github/workflows/update-pre-commit-hooks.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -8,8 +8,8 @@ jobs:
88
update-pre-commit-hooks:
99
runs-on: ubuntu-latest
1010
steps:
11-
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
12-
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065
11+
- uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3
12+
- uses: actions/setup-python@e797f83bcb11b83ae66e0230d6156d7c80228e7c
1313
with:
1414
python-version: "3.13"
1515
- name: Install prerequisites
@@ -28,7 +28,7 @@ jobs:
2828
run: |
2929
make tests
3030
- name: Create Pull Request
31-
uses: peter-evans/create-pull-request@271a8d0340265f705b14b6d32b9829c1cb33d45e
31+
uses: peter-evans/create-pull-request@84ae59a2cdc2258d6fa0732dd66352dddae2a412
3232
with:
3333
token: ${{ secrets.GITHUB_TOKEN }}
3434
commit-message: "build: Update pre-commit hooks"

0 commit comments

Comments
 (0)