Skip to content

Commit dcf5e23

Browse files
Copilotscordio
andcommitted
Pin GitHub Actions dependencies with commit SHAs and update Dependabot config
Co-authored-by: scordio <[email protected]>
1 parent 80ffe23 commit dcf5e23

File tree

5 files changed

+16
-12
lines changed

5 files changed

+16
-12
lines changed

.github/dependabot.yml

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,4 +7,8 @@ updates:
77
- package-ecosystem: "github-actions"
88
directory: "/"
99
schedule:
10-
interval: "daily"
10+
interval: "weekly"
11+
groups:
12+
github-actions:
13+
patterns:
14+
- "*"

.github/workflows/ci.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -12,16 +12,16 @@ jobs:
1212
if: github.event_name == 'pull_request' || (github.event_name == 'push' && github.ref == 'refs/heads/main')
1313

1414
steps:
15-
- uses: actions/setup-java@v4
15+
- uses: actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 # v4.7.1
1616
with:
1717
java-version: 21
1818
distribution: 'temurin'
1919

20-
- uses: actions/checkout@v5
20+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
2121

22-
- uses: gradle/wrapper-validation-action@v3
22+
- uses: gradle/wrapper-validation-action@f9c9c575b8b21b6485636a91ffecd10e558c62f6 # v3.5.0
2323

24-
- uses: gradle/actions/setup-gradle@v4
24+
- uses: gradle/actions/setup-gradle@ed408507eac070d1f99cc633dbcf757c94c7933a # v4.4.3
2525
with:
2626
gradle-version: 8.12.1
2727

.github/workflows/dependabot-auto-merge-patch.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ jobs:
1212
steps:
1313
- name: Dependabot metadata
1414
id: metadata
15-
uses: dependabot/fetch-metadata@v2
15+
uses: dependabot/fetch-metadata@08eff52bf64351f401fb50d4972fa95b9f2c2d1b # v2.4.0
1616
with:
1717
github-token: "${{secrets.GITHUB_TOKEN}}"
1818

.github/workflows/gradle-wrapper-validation.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,5 +6,5 @@ jobs:
66
name: "Validation"
77
runs-on: ubuntu-latest
88
steps:
9-
- uses: actions/checkout@v5
10-
- uses: gradle/wrapper-validation-action@v3
9+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
10+
- uses: gradle/wrapper-validation-action@f9c9c575b8b21b6485636a91ffecd10e558c62f6 # v3.5.0

.github/workflows/release.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -7,17 +7,17 @@ jobs:
77
JVM-Run-Gradle-Release:
88
runs-on: ubuntu-latest
99
steps:
10-
- uses: actions/setup-java@v4
10+
- uses: actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 # v4.7.1
1111
with:
1212
java-version: 17
1313
distribution: 'temurin'
1414

15-
- uses: actions/checkout@v5
15+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
1616

1717
# Given we are doing a release, lets make sure we have a safe gradle install
18-
- uses: gradle/wrapper-validation-action@v3
18+
- uses: gradle/wrapper-validation-action@f9c9c575b8b21b6485636a91ffecd10e558c62f6 # v3.5.0
1919

20-
- uses: gradle/gradle-build-action@v3
20+
- uses: gradle/gradle-build-action@ac2d340dc04d9e1113182899e983b5400c17cda1 # v3.5.0
2121

2222
- name: Verify all checks pass
2323
run: ./gradlew test

0 commit comments

Comments
 (0)