Skip to content

Commit 0ecbcc0

Browse files
authored
SEC-3079 Pin workflow action versions (#197)
1 parent 0a7ed8c commit 0ecbcc0

File tree

3 files changed

+13
-13
lines changed

3 files changed

+13
-13
lines changed

.github/workflows/check.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -14,23 +14,23 @@ jobs:
1414
check:
1515
runs-on: ubuntu-latest
1616
steps:
17-
- uses: actions/checkout@v3
17+
- uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # v3.6.0
1818
- name: Set up JDK
19-
uses: actions/setup-java@v3
19+
uses: actions/setup-java@0ab4596768b603586c0de567f2430c30f5b0d2b0 # v3.13.0
2020
with:
2121
distribution: temurin
2222
java-version: 21
2323
- name: Validate Gradle wrapper
24-
uses: gradle/wrapper-validation-action@v1.0.6
24+
uses: gradle/wrapper-validation-action@8d49e559aae34d3e0eb16cde532684bc9702762b # v1.0.6
2525
- name: Checkstyle
26-
uses: gradle/gradle-build-action@v2
26+
uses: gradle/gradle-build-action@a8f75513eafdebd8141bd1cd4e30fcd194af8dfa # v2.12.0
2727
with:
2828
arguments: checkstyleMain checkstyleTest
2929
- name: PMD
30-
uses: gradle/gradle-build-action@v2
30+
uses: gradle/gradle-build-action@a8f75513eafdebd8141bd1cd4e30fcd194af8dfa # v2.12.0
3131
with:
3232
arguments: pmdMain pmdTest
3333
- name: Test
34-
uses: gradle/gradle-build-action@v2
34+
uses: gradle/gradle-build-action@a8f75513eafdebd8141bd1cd4e30fcd194af8dfa # v2.12.0
3535
with:
3636
arguments: test

.github/workflows/publish.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -12,20 +12,20 @@ jobs:
1212
needs: check
1313
runs-on: ubuntu-latest
1414
steps:
15-
- uses: actions/checkout@v3
15+
- uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # v3.6.0
1616
- name: Set up JDK
17-
uses: actions/setup-java@v3
17+
uses: actions/setup-java@0ab4596768b603586c0de567f2430c30f5b0d2b0 # v3.13.0
1818
with:
1919
distribution: temurin
2020
java-version: 21
2121
- name: Validate Gradle wrapper
22-
uses: gradle/wrapper-validation-action@v1.0.6
22+
uses: gradle/wrapper-validation-action@8d49e559aae34d3e0eb16cde532684bc9702762b # v1.0.6
2323
- name: Build sourcesJar and javadocJar
24-
uses: gradle/gradle-build-action@v2
24+
uses: gradle/gradle-build-action@a8f75513eafdebd8141bd1cd4e30fcd194af8dfa # v2.12.0
2525
with:
2626
arguments: sourcesJar javadocJar
2727
- name: Publish to MavenCentral
28-
uses: gradle/gradle-build-action@v2
28+
uses: gradle/gradle-build-action@a8f75513eafdebd8141bd1cd4e30fcd194af8dfa # v2.12.0
2929
with:
3030
arguments: publishMavenPublicationToSonatypeRepository --max-workers 1 closeAndReleaseSonatypeStagingRepository
3131
env:

.github/workflows/repository-maintenance.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,8 +15,8 @@ jobs:
1515
runs-on: ubuntu-latest
1616
steps:
1717
- name: Checkout sources
18-
uses: actions/checkout@v4.2.1
19-
- uses: actions/setup-java@v4.4.0
18+
uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
19+
- uses: actions/setup-java@b36c23c0d998641eff861008f374ee103c25ac73 # v4.4.0
2020
name: Setup Java
2121
with:
2222
distribution: temurin

0 commit comments

Comments
 (0)