Skip to content

Commit 9427f81

Browse files
committed
chore: Pin GitHub Action refs to specific SHAs
1 parent 8bb1999 commit 9427f81

1 file changed

Lines changed: 7 additions & 7 deletions

File tree

.github/workflows/ci-cd.yaml

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -24,18 +24,18 @@ jobs:
2424
runs-on: ubuntu-latest
2525

2626
steps:
27-
- uses: actions/checkout@v6
27+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # https://github.com/actions/checkout/releases/tag/v6.0.2
2828
with:
2929
fetch-depth: 0
3030

3131
- name: Set up JDK 21
32-
uses: actions/setup-java@v5
32+
uses: actions/setup-java@be666c2fcd27ec809703dec50e508c2fdc7f6654 # https://github.com/actions/setup-java/releases/tag/v5.2.0
3333
with:
3434
distribution: "temurin"
3535
java-version: "21"
3636

3737
- name: Set up Gradle
38-
uses: gradle/actions/setup-gradle@v6
38+
uses: gradle/actions/setup-gradle@39e147cb9de83bb9910b8ef8bd7fff0ee20fcd6f # https://github.com/gradle/actions/releases/tag/v6.0.1
3939
with:
4040
cache-read-only: false
4141

@@ -103,14 +103,14 @@ jobs:
103103
104104
- name: Upload Gradle profile report
105105
if: always()
106-
uses: actions/upload-artifact@v7
106+
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # https://github.com/actions/upload-artifact/releases/tag/v7.0.0
107107
with:
108108
name: gradle-profile
109109
path: build/reports/profile/profile-*.html
110110
retention-days: 1
111111

112112
- name: Upload build artifact
113-
uses: actions/upload-artifact@v7
113+
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # https://github.com/actions/upload-artifact/releases/tag/v7.0.0
114114
with:
115115
name: points-shadow-jar
116116
path: build/libs/*-all.jar
@@ -124,7 +124,7 @@ jobs:
124124

125125
steps:
126126
- name: Download release artifacts
127-
uses: actions/download-artifact@v8
127+
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # https://github.com/actions/download-artifact/releases/tag/v8.0.1
128128
with:
129129
pattern: points-shadow-jar
130130
path: build/libs
@@ -138,7 +138,7 @@ jobs:
138138
echo "RELEASE_ID=${{ github.event.release.id }}" >> "$GITHUB_ENV"
139139
140140
- name: Upload release assets
141-
uses: actions/github-script@v8
141+
uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # https://github.com/actions/github-script/releases/tag/v8
142142
with:
143143
github-token: ${{ secrets.GITHUB_TOKEN }}
144144
script: |

0 commit comments

Comments
 (0)