Skip to content

Commit 7913cbc

Browse files
committed
chore(deps): update github-actions
1 parent 8c65cc3 commit 7913cbc

13 files changed

+37
-37
lines changed

.github/actions/ossf-compiler-flags-scanner/action.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@ inputs:
2828
runs:
2929
using: composite
3030
steps:
31-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # ratchet:actions/checkout@v4.2.2
31+
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
3232
with:
3333
repository: ossf/wg-best-practices-os-developers
3434
sparse-checkout: docs/Compiler-Hardening-Guides/compiler-options-scraper
@@ -57,6 +57,6 @@ runs:
5757
# Upload the results to GitHub's code scanning dashboard.
5858
- name: "Upload to code-scanning"
5959
if: ${{ !cancelled() && inputs.upload == 'true' }}
60-
uses: github/codeql-action/upload-sarif@ff0a06e83cb2de871e5a09832bc6a81e7276941f # ratchet:github/codeql-action/upload-sarif@v3.29.7
60+
uses: github/codeql-action/upload-sarif@ff0a06e83cb2de871e5a09832bc6a81e7276941f # ratchet:github/codeql-action/upload-sarif@v3.30.3
6161
with:
6262
sarif_file: results.sarif

.github/workflows/github-actions-checker.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ jobs:
3434
runs-on: 'ubuntu-latest'
3535
name: 'ratchet'
3636
steps:
37-
- uses: 'actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683' # ratchet:actions/checkout@v4.2.2
37+
- uses: 'actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955' # v4.3.0
3838
- id: files
3939
run: |
4040
FILES=$(find .github/ -name "*.yml" -o -name "*.yaml" -printf "%p ")

.github/workflows/license-scanner.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@ jobs:
3535
run-scan:
3636
runs-on: ubuntu-latest
3737
steps:
38-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # ratchet:actions/checkout@v4.2.2
38+
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
3939
with:
4040
fetch-depth: '0'
4141
- uses: erlef/setup-beam@e6d7c94229049569db56a7ad5a540c051a010af9 # v1.20.4

.github/workflows/main.yaml

Lines changed: 18 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -68,7 +68,7 @@ jobs:
6868
build-c-code: ${{ steps.c-code-changes.outputs.changes != '[]' || env.FULL_BUILD_AND_CHECK == 'true' }}
6969
all: ${{ steps.apps.outputs.all }}
7070
steps:
71-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # ratchet:actions/checkout@v4.2.2
71+
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
7272
- uses: ./.github/actions/build-base-image
7373
with:
7474
BASE_BRANCH: ${{ env.BASE_BRANCH }}
@@ -197,7 +197,7 @@ jobs:
197197
WXWIDGETS_VERSION: 3.2.6
198198
MACOS_VERSION: 15
199199
steps:
200-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # ratchet:actions/checkout@v4.2.2
200+
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
201201

202202
- name: Download source archive
203203
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # ratchet:actions/[email protected]
@@ -246,7 +246,7 @@ jobs:
246246
needs: pack
247247
if: needs.pack.outputs.build-c-code == 'true'
248248
steps:
249-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # ratchet:actions/checkout@v4.2.2
249+
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
250250
- name: Download source archive
251251
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # ratchet:actions/[email protected]
252252
with:
@@ -385,7 +385,7 @@ jobs:
385385
fail-fast: false
386386

387387
steps:
388-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # ratchet:actions/checkout@v4.2.2
388+
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
389389
- uses: ./.github/actions/build-base-image
390390
with:
391391
BASE_BRANCH: ${{ env.BASE_BRANCH }}
@@ -464,7 +464,7 @@ jobs:
464464
outputs:
465465
vendor-files: ${{ steps.vendor-files.outputs.MODIFIED_FILES != '0' }}
466466
steps:
467-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # ratchet:actions/checkout@v4.2.2
467+
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
468468
with:
469469
fetch-depth: 0
470470
- name: Get modified vendor files
@@ -500,7 +500,7 @@ jobs:
500500
fail-fast: false
501501

502502
steps:
503-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # ratchet:actions/checkout@v4.2.2
503+
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
504504
- uses: ./.github/actions/build-base-image
505505
with:
506506
BASE_BRANCH: ${{ env.BASE_BRANCH }}
@@ -517,7 +517,7 @@ jobs:
517517
with:
518518
name: otp_prebuilt
519519
- name: Build on FreeBSD
520-
uses: vmactions/freebsd-vm@966989c456d41351f095a421f60e71342d3bce41 # v1
520+
uses: vmactions/freebsd-vm@05856381fab64eeee9b038a0818f6cec649ca17a # v1
521521
with:
522522
usesh: true
523523
copyback: false
@@ -546,7 +546,7 @@ jobs:
546546
with:
547547
name: otp_prebuilt
548548
- name: Build on OpenBSD
549-
uses: vmactions/openbsd-vm@0d65352eee1508bab7cb12d130536d3a556be487 # v1.1.8
549+
uses: vmactions/openbsd-vm@1e7cc4fa7727646d3cf5921289b1f5c9d1a88f3c # v1.2.0
550550
with:
551551
usesh: true
552552
copyback: false
@@ -572,7 +572,7 @@ jobs:
572572
with:
573573
name: otp_prebuilt
574574
- name: Build on Solaris
575-
uses: vmactions/solaris-vm@170f1f96f376cf7467cc41627e0c7590932fccaa # v1.1.4
575+
uses: vmactions/solaris-vm@58cbd70c6e051860f9b8f65908cc582938fbbdba # v1.1.5
576576
with:
577577
usesh: true
578578
copyback: false
@@ -592,7 +592,7 @@ jobs:
592592
runs-on: ubuntu-latest
593593
needs: pack
594594
steps:
595-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # ratchet:actions/checkout@v4.2.2
595+
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
596596
- uses: ./.github/actions/build-base-image
597597
with:
598598
BASE_BRANCH: ${{ env.BASE_BRANCH }}
@@ -646,7 +646,7 @@ jobs:
646646
runs-on: ubuntu-latest
647647
needs: pack
648648
steps:
649-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # ratchet:actions/checkout@v4.2.2
649+
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
650650
- uses: ./.github/actions/build-base-image
651651
with:
652652
BASE_BRANCH: ${{ env.BASE_BRANCH }}
@@ -671,7 +671,7 @@ jobs:
671671
# type: ["os_mon","sasl"]
672672
fail-fast: false
673673
steps:
674-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # ratchet:actions/checkout@v4.2.2
674+
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
675675
- uses: ./.github/actions/build-base-image
676676
with:
677677
BASE_BRANCH: ${{ env.BASE_BRANCH }}
@@ -724,7 +724,7 @@ jobs:
724724
if: ${{ !cancelled() }} # Run even if the need has failed
725725
needs: test
726726
steps:
727-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # ratchet:actions/checkout@v4.2.2
727+
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
728728
- uses: ./.github/actions/build-base-image
729729
with:
730730
BASE_BRANCH: ${{ env.BASE_BRANCH }}
@@ -801,13 +801,13 @@ jobs:
801801
- name: Use HTTPS instead of SSH for Git cloning
802802
run: git config --global url.https://github.com/.insteadOf ssh://[email protected]/
803803

804-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # ratchet:actions/checkout@v4.2.2
804+
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
805805
- uses: ./.github/actions/build-base-image
806806
with:
807807
BASE_BRANCH: ${{ env.BASE_BRANCH }}
808808

809809
- name: Fetch Default ORT Config
810-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # ratchet:actions/checkout@v4
810+
uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4
811811
with:
812812
repository: oss-review-toolkit/ort-config
813813
ref: "d2978deb230beae095bb6cfec074b94f1a74fd34"
@@ -973,7 +973,7 @@ jobs:
973973
contents: write
974974
id-token: write
975975
steps:
976-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # ratchet:actions/checkout@v4.2.2
976+
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
977977
- uses: ./.github/actions/build-base-image
978978
with:
979979
BASE_BRANCH: ${{ env.BASE_BRANCH }}
@@ -1024,7 +1024,7 @@ jobs:
10241024
echo "tag=${TAG}" >> $GITHUB_OUTPUT
10251025
echo "vsn=${VSN}" >> $GITHUB_OUTPUT
10261026
1027-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # ratchet:actions/checkout@v4.2.2
1027+
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
10281028

10291029
## Publish the pre-built archive and docs
10301030
- name: Download source archive
@@ -1094,7 +1094,7 @@ jobs:
10941094
path: "attestations/*.sigstore"
10951095

10961096
- name: Upload pre-built and doc tar archives
1097-
uses: softprops/action-gh-release@72f2c25fcb47643c292f7107632f7a47c1df5cd8 # v2.3.2
1097+
uses: softprops/action-gh-release@6cbd405e2c4e67a21c47fa9e383d020e4e28b836 # v2.3.3
10981098
with:
10991099
name: OTP ${{ steps.tag.outputs.vsn }}
11001100
files: |

.github/workflows/openvex-sync.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -39,11 +39,11 @@ jobs:
3939
contents: write
4040
pull-requests: write
4141
steps:
42-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # ratchet:actions/checkout@v4.2.2
42+
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
4343
with:
4444
ref: 'master' # '' = default branch
4545

46-
- uses: erlef/setup-beam@5304e04ea2b355f03681464e683d92e3b2f18451 # racket:actions/checkout@v1
46+
- uses: erlef/setup-beam@033f1034211ab8be21f54cbd0547fbb06e31860f # racket:actions/checkout@v1
4747
with:
4848
otp-version: '28'
4949

.github/workflows/ossf-compiler-flags-scanner.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -44,7 +44,7 @@ jobs:
4444
# Only need to read contents
4545
contents: read
4646
steps:
47-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # ratchet:actions/checkout@v4.2.2
47+
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
4848
- name: Create initial pre-release tar
4949
run: .github/scripts/init-pre-release.sh otp_src.tar.gz
5050
- uses: ./.github/actions/build-base-image

.github/workflows/osv-scanner-scheduled.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -39,7 +39,7 @@ jobs:
3939
outputs:
4040
versions: ${{ steps.get-versions.outputs.versions }}
4141
steps:
42-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # ratchet:actions/checkout@v4.2.2
42+
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
4343
- id: get-versions
4444
name: Fetch latest 3 OTP versions
4545
run: |

.github/workflows/pr-comment.yaml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -44,7 +44,7 @@ jobs:
4444
outputs:
4545
result: ${{ steps.pr-number.outputs.result }}
4646
steps:
47-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # ratchet:actions/checkout@v4.2.2
47+
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
4848
- uses: erlef/setup-beam@e6d7c94229049569db56a7ad5a540c051a010af9 # v1.20.4
4949
with:
5050
otp-version: '27'
@@ -64,9 +64,9 @@ jobs:
6464
pull-requests: write
6565
if: github.event.action == 'requested' && needs.pr-number.outputs.result != ''
6666
steps:
67-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # ratchet:actions/checkout@v4.2.2
67+
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
6868
## We create an initial comment with some useful help to the user
69-
- uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # ratchet:actions/github-script@v7.0.1
69+
- uses: actions/github-script@f28e40c7f34bde8b3046d885e986cb6290c5673b # v7.1.0
7070
with:
7171
script: |
7272
const script = require('./.github/scripts/pr-comment.js');
@@ -87,7 +87,7 @@ jobs:
8787
needs.pr-number.outputs.result != '' &&
8888
github.event.workflow_run.conclusion != 'skipped'
8989
steps:
90-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # ratchet:actions/checkout@v4.2.2
90+
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
9191
- name: Download and Extract Artifacts
9292
id: extract
9393
env:
@@ -124,7 +124,7 @@ jobs:
124124

125125
## Append some useful links and tips to the test results posted by
126126
## Publish CT Test Results
127-
- uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # ratchet:actions/github-script@v7.0.1
127+
- uses: actions/github-script@f28e40c7f34bde8b3046d885e986cb6290c5673b # v7.1.0
128128
if: always()
129129
with:
130130
script: |

.github/workflows/renovate-vendored-deps.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ jobs:
3434
runs-on: ubuntu-latest
3535
if: contains(github.event.pull_request.title, 'Update dependency') && github.actor == 'renovate-bot'
3636
steps:
37-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # ratchet:actions/checkout@v4.2.2
37+
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
3838
with:
3939
repository: ${{ github.event.pull_request.head.repo.full_name }}
4040
ref: ${{ github.event.pull_request.head.ref }}

.github/workflows/reusable-vendor-vulnerability-scanner.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -95,11 +95,11 @@ jobs:
9595
security-events: read
9696
issues: write
9797
steps:
98-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # ratchet:actions/checkout@v4.2.2
98+
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
9999
with:
100100
ref: ${{ inputs.checkout && inputs.version || ''}} # '' = default branch
101101

102-
- uses: erlef/setup-beam@5304e04ea2b355f03681464e683d92e3b2f18451 # racket:actions/checkout@v1
102+
- uses: erlef/setup-beam@033f1034211ab8be21f54cbd0547fbb06e31860f # racket:actions/checkout@v1
103103
with:
104104
otp-version: '28'
105105

0 commit comments

Comments
 (0)