diff --git a/.github/workflows/changelog-check.yaml b/.github/workflows/changelog-check.yaml index 5f1a382..f5b32b6 100644 --- a/.github/workflows/changelog-check.yaml +++ b/.github/workflows/changelog-check.yaml @@ -9,7 +9,7 @@ jobs: runs-on: ubuntu-latest if: "!startsWith(github.event.pull_request.title, 'version:')" steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # actions/checkout@v4 - run: git fetch --depth=1 origin main - name: Setup Python ${{ env.PYTHON_VERSION }} environment @@ -34,7 +34,7 @@ jobs: - name: Get latest changie version id: latest - uses: miniscruff/changie-action@v2 + uses: miniscruff/changie-action@6dcc2533cac0495148ed4046c438487e4dceaa23 # miniscruff/changie-action@v2 with: version: latest args: latest diff --git a/.github/workflows/code-quality.yaml b/.github/workflows/code-quality.yaml index 5fc1d94..ed5ae54 100644 --- a/.github/workflows/code-quality.yaml +++ b/.github/workflows/code-quality.yaml @@ -21,7 +21,7 @@ jobs: code-quality: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # actions/checkout@v4 - uses: ./.github/actions/setup-python-env diff --git a/.github/workflows/create-release-pr.yaml b/.github/workflows/create-release-pr.yaml index 5ddb084..02e5423 100644 --- a/.github/workflows/create-release-pr.yaml +++ b/.github/workflows/create-release-pr.yaml @@ -15,25 +15,25 @@ jobs: create-release-pr: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # actions/checkout@v4 - uses: ./.github/actions/setup-python-env - name: Batch changes - uses: miniscruff/changie-action@v2 + uses: miniscruff/changie-action@6dcc2533cac0495148ed4046c438487e4dceaa23 # miniscruff/changie-action@v2 with: version: latest args: batch ${{ inputs.bump }} - name: Merge - uses: miniscruff/changie-action@v2 + uses: miniscruff/changie-action@6dcc2533cac0495148ed4046c438487e4dceaa23 # miniscruff/changie-action@v2 with: version: latest args: merge - name: Get the latest version id: changie-latest - uses: miniscruff/changie-action@v2 + uses: miniscruff/changie-action@6dcc2533cac0495148ed4046c438487e4dceaa23 # miniscruff/changie-action@v2 with: version: latest args: latest @@ -55,7 +55,7 @@ jobs: - name: Create Pull Request - uses: peter-evans/create-pull-request@v4 + uses: peter-evans/create-pull-request@38e0b6e68b4c852a5500a94740f0e535e0d7ba54 # peter-evans/create-pull-request@v4 with: title: "version: ${{ steps.package-version.outputs.version }}" branch: release/${{ steps.package-version.outputs.version }} diff --git a/.github/workflows/create-release-tag.yaml b/.github/workflows/create-release-tag.yaml index d24bda6..17984d4 100644 --- a/.github/workflows/create-release-tag.yaml +++ b/.github/workflows/create-release-tag.yaml @@ -12,7 +12,7 @@ jobs: runs-on: ubuntu-latest if: "startsWith(github.event.head_commit.message, 'version:')" steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # actions/checkout@v4 - uses: ./.github/actions/setup-python-env - name: Create tag run: | diff --git a/.github/workflows/publish-test.yaml b/.github/workflows/publish-test.yaml index f03cb98..f6a5689 100644 --- a/.github/workflows/publish-test.yaml +++ b/.github/workflows/publish-test.yaml @@ -13,7 +13,7 @@ jobs: steps: - name: Check-out the repo - uses: actions/checkout@v3 + uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # actions/checkout@v3 - name: Setup Python ${{ env.PYTHON_VERSION }} environment uses: ./.github/actions/setup-python-env @@ -24,7 +24,7 @@ jobs: run: hatch build - name: Publish package distributions to PyPI - uses: pypa/gh-action-pypi-publish@release/v1 + uses: pypa/gh-action-pypi-publish@ed0c53931b1dc9bd32cbe73a98c7f6766f8a527e # pypa/gh-action-pypi-publish@release/v1 with: repository-url: "https://test.pypi.org/legacy/" diff --git a/.github/workflows/publish.yaml b/.github/workflows/publish.yaml index 4d92f4e..8a2cc6c 100644 --- a/.github/workflows/publish.yaml +++ b/.github/workflows/publish.yaml @@ -23,7 +23,7 @@ jobs: id-token: write steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # actions/checkout@v4 - uses: ./.github/actions/setup-python-env @@ -31,5 +31,5 @@ jobs: run: hatch build - name: Publish package distributions to PyPI - uses: pypa/gh-action-pypi-publish@release/v1 + uses: pypa/gh-action-pypi-publish@ed0c53931b1dc9bd32cbe73a98c7f6766f8a527e # pypa/gh-action-pypi-publish@release/v1