Skip to content

Commit a27a5ce

Browse files
committed
Pin GitHub Actions to commit SHAs for supply chain security
1 parent 99ec929 commit a27a5ce

2 files changed

Lines changed: 9 additions & 9 deletions

File tree

.github/workflows/ci.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -10,8 +10,8 @@ jobs:
1010
build:
1111
runs-on: ubuntu-latest
1212
steps:
13-
- uses: actions/checkout@v4
14-
- uses: actions/setup-dotnet@v4
13+
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
14+
- uses: actions/setup-dotnet@67a3573c9a986a3f9c594539f4ab511d57bb3ce9 # v4.3.1
1515
with:
1616
dotnet-version: '10.0.x'
1717
- run: dotnet restore

.github/workflows/release.yml

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -20,8 +20,8 @@ jobs:
2020
artifact: git-wt-win-x64
2121
runs-on: ${{ matrix.os }}
2222
steps:
23-
- uses: actions/checkout@v4
24-
- uses: actions/setup-dotnet@v4
23+
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
24+
- uses: actions/setup-dotnet@67a3573c9a986a3f9c594539f4ab511d57bb3ce9 # v4.3.1
2525
with:
2626
dotnet-version: '10.0.x'
2727
- name: Set version from tag
@@ -36,7 +36,7 @@ jobs:
3636
-p:PublishAot=true
3737
-o ./publish
3838
- name: Upload artifact
39-
uses: actions/upload-artifact@v4
39+
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
4040
with:
4141
name: ${{ matrix.artifact }}
4242
path: ./publish/git-wt*
@@ -48,8 +48,8 @@ jobs:
4848
permissions:
4949
contents: write
5050
steps:
51-
- uses: actions/checkout@v4
52-
- uses: actions/setup-dotnet@v4
51+
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
52+
- uses: actions/setup-dotnet@67a3573c9a986a3f9c594539f4ab511d57bb3ce9 # v4.3.1
5353
with:
5454
dotnet-version: '10.0.x'
5555
- name: Set version from tag
@@ -61,7 +61,7 @@ jobs:
6161
- name: Push to NuGet
6262
run: dotnet nuget push ./artifacts/*.nupkg --api-key ${{ secrets.NUGET_API_KEY }} --source https://api.nuget.org/v3/index.json
6363
- name: Download native binaries
64-
uses: actions/download-artifact@v4
64+
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
6565
with:
6666
path: ./native
6767
- name: Package native binaries
@@ -72,7 +72,7 @@ jobs:
7272
tar -czf "../artifacts/${name}.tar.gz" -C "$dir" .
7373
done
7474
- name: Create GitHub Release
75-
uses: softprops/action-gh-release@v2
75+
uses: softprops/action-gh-release@153bb8e04406b158c6c84fc1615b65b24149a1fe # v2.6.1
7676
with:
7777
files: artifacts/*
7878
generate_release_notes: true

0 commit comments

Comments
 (0)