File tree Expand file tree Collapse file tree 11 files changed +65
-17
lines changed Expand file tree Collapse file tree 11 files changed +65
-17
lines changed Original file line number Diff line number Diff line change 2121      name : Auto label pull requests 
2222      runs-on : ubuntu-latest 
2323      steps :
24-         - uses : release-drafter/release-drafter@v6  
24+         - uses : release-drafter/release-drafter@3f0f87098bd6b5c5b9a36d49c41d998ea58f9348  
2525          env :
2626            GITHUB_TOKEN : ${{ secrets.GITHUB_TOKEN }} 
2727          with :
Original file line number Diff line number Diff line change 2929          echo "END_DATE=$end_date" >> "$GITHUB_ENV" 
3030
3131name : Run contributor action 
32-         uses : github/contributors@v1  
32+         uses : github/contributors@832b6518181710ef277bc9ddafda6696e6b312bd  
3333        env :
3434          GH_TOKEN : ${{ secrets.GITHUB_TOKEN }} 
3535          START_DATE : ${{ env.START_DATE }} 
3838          SPONSOR_INFO : " true" 
3939
4040      - name : Create issue 
41-         uses : peter-evans/create-issue-from-file@v5  
41+         uses : peter-evans/create-issue-from-file@24452a72d85239eacf1468b0f1982a9f3fec4c94  
4242        with :
4343          title : Monthly contributor report 
4444          token : ${{ secrets.GITHUB_TOKEN }} 
Original file line number Diff line number Diff line change 1414  build :
1515    runs-on : ubuntu-latest 
1616    steps :
17-       - uses : actions/checkout@v4  
17+       - uses : actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b  
1818      - name : Build the Docker image 
1919        run : docker build . --file Dockerfile --platform linux/amd64 
Original file line number Diff line number Diff line change 1515      contents : write 
1616    steps :
1717      - name : Checkout Repo 
18-         uses : actions/checkout@v4  
18+         uses : actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b  
1919
2020      - name : version 
2121        id : version 
Original file line number Diff line number Diff line change 2020    name : Validate PR title 
2121    runs-on : ubuntu-latest 
2222    steps :
23-       - uses : amannn/action-semantic-pull-request@v5  
23+       - uses : amannn/action-semantic-pull-request@e9fabac35e210fea40ca5b14c0da95a099eff26f  
2424        env :
2525          GITHUB_TOKEN : ${{ secrets.GITHUB_TOKEN }} 
2626        with :
Original file line number Diff line number Diff line change 2020      matrix :
2121        python-version : [3.11, 3.12] 
2222    steps :
23-       - uses : actions/checkout@v4  
23+       - uses : actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b  
2424      - name : Set up Python ${{ matrix.python-version }} 
25-         uses : actions/setup-python@v5  
25+         uses : actions/setup-python@82c7e631bb3cdc910f68e0081d67478d79c6982d  
2626        with :
2727          python-version : ${{ matrix.python-version }} 
2828      - name : Install dependencies 
Original file line number Diff line number Diff line change 3333        contents : write 
3434        pull-requests : read 
3535      steps :
36-         - uses : release-drafter/release-drafter@v6  
36+         - uses : release-drafter/release-drafter@3f0f87098bd6b5c5b9a36d49c41d998ea58f9348  
3737          id : release-drafter 
3838          env :
3939            GITHUB_TOKEN : ${{ secrets.GITHUB_TOKEN }} 
5555        IMAGE_NAME : ${{ github.repository }} 
5656      steps :
5757        - name : Set up Docker Buildx 
58-           uses : docker/setup-buildx-action@v3  
58+           uses : docker/setup-buildx-action@d70bba72b1f3fd22344832f00baa16ece964efeb  
5959        - name : Log in to the Container registry 
60-           uses : docker/login-action@v3  
60+           uses : docker/login-action@e92390c5fb421da1463c202d546fed0ec5c39f20  
6161          with :
6262            registry : ${{ env.REGISTRY }} 
6363            username : ${{ github.actor }} 
6464            password : ${{ secrets.GITHUB_TOKEN }} 
65-         - uses : actions/checkout@v4  
65+         - uses : actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b  
6666        - name : Push Docker Image 
6767          if : ${{ success() }} 
68-           uses : docker/build-push-action@v5  
68+           uses : docker/build-push-action@2cdde995de11925a030ce8070c3d77a52ffcf1c0  
6969          with :
7070            context : . 
7171            file : ./Dockerfile 
8484        discussions : write 
8585      steps :
8686        - name : Create an announcement discussion for release 
87-           uses : abirismyname/create-discussion@v1.2.0  
87+           uses : abirismyname/create-discussion@6e6ef67e5eeb042343ef8b3d8d0f5d545cbdf024  
8888          env :
8989            GH_TOKEN : ${{ secrets.GITHUB_TOKEN }} 
9090          with :
Original file line number Diff line number Diff line change 1+ ---
2+ name : Scorecard supply-chain security 
3+ on :
4+   workflow_dispatch :
5+   #  For Branch-Protection check (for repo branch protection or rules).
6+   #  Only the default branch is supported. See
7+   #  https://github.com/ossf/scorecard/blob/main/docs/checks.md#branch-protection
8+   branch_protection_rule :
9+   #  To guarantee Maintained check is occasionally updated. See
10+   #  https://github.com/ossf/scorecard/blob/main/docs/checks.md#maintained
11+   schedule :
12+     - cron : ' 29 11 * * 6' 
13+   push :
14+     branches : ["main"] 
15+ 
16+ permissions : read-all 
17+ 
18+ jobs :
19+   analysis :
20+     name : Merge to Main Scorecard analysis 
21+     runs-on : ubuntu-latest 
22+     permissions :
23+       security-events : write 
24+       id-token : write 
25+ 
26+     steps :
27+       - name : " Checkout code" 
28+         uses : actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11  #  v4.1.1
29+         with :
30+           persist-credentials : false 
31+ 
32+       - name : " Run analysis" 
33+         uses : ossf/scorecard-action@0864cf19026789058feabb7e87baa5f140aac736  #  v2.3.1
34+         with :
35+           results_file : results.sarif 
36+           results_format : sarif 
37+           publish_results : true 
38+       - name : " Upload artifact" 
39+         uses : actions/upload-artifact@97a0fba1372883ab732affbe8f94b823f91727db  #  v3.pre.node20
40+         with :
41+           name : SARIF file 
42+           path : results.sarif 
43+           retention-days : 5 
44+       - name : " Upload to code-scanning" 
45+         uses : github/codeql-action/upload-sarif@1b1aada464948af03b950897e5eb522f92603cc2  #  v3.24.9
46+         with :
47+           sarif_file : results.sarif 
Original file line number Diff line number Diff line change 1313      issues : write 
1414      pull-requests : read 
1515    steps :
16-       - uses : actions/stale@v9  
16+       - uses : actions/stale@28ca1036281a5e5922ead5184a1bbf96e5fc984e  
1717        with :
1818          stale-issue-message : ' This issue is stale because it has been open 21 days with no activity. Remove stale label or comment or this will be closed in 14 days.' 
1919          close-issue-message : ' This issue was closed because it has been stalled for 35 days with no activity.' 
Original file line number Diff line number Diff line change @@ -19,15 +19,15 @@ jobs:
1919
2020    steps :
2121      - name : Checkout Code 
22-         uses : actions/checkout@v4  
22+         uses : actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b  
2323        with :
2424          fetch-depth : 0 
2525      - name : Install dependencies 
2626        run : | 
2727          python -m pip install --upgrade pip 
2828          pip install -r requirements.txt -r requirements-test.txt 
2929name : Lint Code Base 
30-         uses : super-linter/super-linter@v6  
30+         uses : super-linter/super-linter@4758be622215d0954c8353ee4877ffd60111cf8e  
3131        env :
3232          DEFAULT_BRANCH : main 
3333          GITHUB_TOKEN : ${{ secrets.GITHUB_TOKEN }} 
 
 
   
 
     
   
   
          
    
    
     
    
      
     
     
    You can’t perform that action at this time.
  
 
    
  
    
      
        
     
       
      
     
   
 
    
    
  
 
  
 
     
    
0 commit comments