diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index c789e317..d0f449df 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -31,7 +31,7 @@ jobs: - 5432:5432 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4 with: fetch-depth: 0 # fetch all history @@ -41,7 +41,7 @@ jobs: - name: Apt install run: sudo apt-get install -y libxmlsec1-dev - - uses: eifinger/setup-rye@v4 + - uses: eifinger/setup-rye@a64bd427414a77fd506d9a85a590ab36d71cf86a # v4 id: setup-rye - name: Pin python-version ${{ matrix.python-version }} @@ -68,14 +68,14 @@ jobs: runs-on: ubuntu-22.04 if: startsWith(github.ref, 'refs/tags/') steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4 - - uses: eifinger/setup-rye@v4 + - uses: eifinger/setup-rye@a64bd427414a77fd506d9a85a590ab36d71cf86a # v4 id: setup-rye # extract the app name out of the tag's ref value - id: get-app-name - uses: actions/github-script@v7 + uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7 with: script: | const appName = context.ref.match(/refs\/tags\/([a-z\-]+)\/v\S+$/)[1] diff --git a/.github/workflows/renovate.yml b/.github/workflows/renovate.yml index 6fa79afb..5cc8e811 100644 --- a/.github/workflows/renovate.yml +++ b/.github/workflows/renovate.yml @@ -12,16 +12,16 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v4.1.6 + uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6 - name: Apt install run: sudo apt-get update && sudo apt-get install -y libxmlsec1-dev - - uses: eifinger/setup-rye@v4 + - uses: eifinger/setup-rye@a64bd427414a77fd506d9a85a590ab36d71cf86a # v4 id: setup-rye - name: Self-hosted Renovate - uses: renovatebot/github-action@v40.2.4 + uses: renovatebot/github-action@76d49712364696a06b60e8647df46b288fff0ddc # v40.2.4 with: configurationFile: renovate-config.json token: ${{ secrets.GITHUB_TOKEN }}