Skip to content

Commit c303b1f

Browse files
authored
Pin workflow actions to specific SHA (latest minor version) (#4831)
1 parent 94afef6 commit c303b1f

File tree

3 files changed

+21
-21
lines changed

3 files changed

+21
-21
lines changed

.github/workflows/publish.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,8 +11,8 @@ jobs:
1111
id-token: write
1212
contents: read
1313
steps:
14-
- uses: actions/checkout@v4
15-
- uses: actions/setup-node@v4
14+
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # actions/checkout@v4
15+
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # actions/setup-node@v4
1616
with:
1717
node-version: '22.x'
1818
registry-url: 'https://registry.npmjs.org'

.github/workflows/size.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,9 +8,9 @@ jobs:
88
runs-on: ubuntu-latest
99

1010
steps:
11-
- uses: actions/checkout@v4
11+
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # actions/checkout@v4
1212
with:
1313
fetch-depth: 1
14-
- uses: preactjs/compressed-size-action@v2
14+
- uses: preactjs/compressed-size-action@946a292cd35bd1088e0d7eb92b69d1a8d5b5d76a # preactjs/compressed-size-action@v2
1515
with:
1616
repo-token: '${{ secrets.GITHUB_TOKEN }}'

.github/workflows/test.yaml

Lines changed: 17 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -8,8 +8,8 @@ jobs:
88
outputs:
99
src: ${{ steps.filter.outputs.src }}
1010
steps:
11-
- uses: actions/checkout@v4
12-
- uses: dorny/paths-filter@v3
11+
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # actions/checkout@v4
12+
- uses: dorny/paths-filter@de90cc6fb38fc0963ad72b210f1f284cd68cea36 #dorny/paths-filter@v3
1313
id: filter
1414
with:
1515
filters: |
@@ -34,10 +34,10 @@ jobs:
3434

3535
steps:
3636
- name: Checkout repo
37-
uses: actions/checkout@v4
37+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # actions/checkout@v4
3838

3939
- name: Use node ${{ matrix.node }}
40-
uses: actions/setup-node@v4
40+
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # actions/setup-node@v4
4141
with:
4242
node-version: ${{ matrix.node }}
4343
cache: 'yarn'
@@ -57,7 +57,7 @@ jobs:
5757
- name: Pack
5858
run: yarn pack
5959

60-
- uses: actions/upload-artifact@v4
60+
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 #actions/upload-artifact@v4
6161
with:
6262
name: package
6363
path: ./package.tgz
@@ -72,18 +72,18 @@ jobs:
7272
node: ['22.x']
7373
steps:
7474
- name: Checkout repo
75-
uses: actions/checkout@v4
75+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # actions/checkout@v4
7676

7777
- name: Use node ${{ matrix.node }}
78-
uses: actions/setup-node@v4
78+
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # actions/setup-node@v4
7979
with:
8080
node-version: ${{ matrix.node }}
8181
cache: 'yarn'
8282

8383
- name: Install deps
8484
run: yarn install
8585

86-
- uses: actions/download-artifact@v4
86+
- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 #actions/download-artifact@v4
8787
with:
8888
name: package
8989
path: .
@@ -113,10 +113,10 @@ jobs:
113113
ts: ['5.0', '5.1', '5.2', '5.3', '5.4', '5.5', '5.6', '5.7', '5.8']
114114
steps:
115115
- name: Checkout repo
116-
uses: actions/checkout@v4
116+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # actions/checkout@v4
117117

118118
- name: Use node ${{ matrix.node }}
119-
uses: actions/setup-node@v4
119+
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # actions/setup-node@v4
120120
with:
121121
node-version: ${{ matrix.node }}
122122
cache: 'yarn'
@@ -127,7 +127,7 @@ jobs:
127127
- name: Install TypeScript ${{ matrix.ts }}
128128
run: yarn add typescript@${{ matrix.ts }}
129129

130-
- uses: actions/download-artifact@v4
130+
- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 #actions/download-artifact@v4
131131
with:
132132
name: package
133133
path: .
@@ -156,15 +156,15 @@ jobs:
156156
node: ['22.x']
157157
steps:
158158
- name: Checkout repo
159-
uses: actions/checkout@v4
159+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # actions/checkout@v4
160160

161161
- name: Use node ${{ matrix.node }}
162-
uses: actions/setup-node@v4
162+
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # actions/setup-node@v4
163163
with:
164164
node-version: ${{ matrix.node }}
165165
cache: 'yarn'
166166

167-
- uses: actions/download-artifact@v4
167+
- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 #actions/download-artifact@v4
168168
with:
169169
name: package
170170
path: .
@@ -195,10 +195,10 @@ jobs:
195195
]
196196
steps:
197197
- name: Checkout repo
198-
uses: actions/checkout@v4
198+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # actions/checkout@v4
199199

200200
- name: Use node ${{ matrix.node }}
201-
uses: actions/setup-node@v4
201+
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # actions/setup-node@v4
202202
with:
203203
node-version: ${{ matrix.node }}
204204
cache: 'yarn'
@@ -221,7 +221,7 @@ jobs:
221221
YARN_ENABLE_IMMUTABLE_INSTALLS: false
222222
run: yarn install
223223

224-
- uses: actions/download-artifact@v4
224+
- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 #actions/download-artifact@v4
225225
with:
226226
name: package
227227
path: ./redux-toolkit/examples/publish-ci/${{ matrix.example }}

0 commit comments

Comments
 (0)