diff --git a/.github/actions/bootstrap/action.yml b/.github/actions/bootstrap/action.yml index 21c24fd..a8b7d6a 100644 --- a/.github/actions/bootstrap/action.yml +++ b/.github/actions/bootstrap/action.yml @@ -11,7 +11,7 @@ runs: - name: Restore asdf cache id: asdf-cache-restore - uses: actions/cache/restore@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 with: key: asdf-tools-v1-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('.tool-versions') }} path: | @@ -32,7 +32,7 @@ runs: - name: Save asdf cache if: always() && steps.asdf-cache-restore.outputs.cache-hit != 'true' - uses: actions/cache/save@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 with: key: ${{ steps.asdf-cache-restore.outputs.cache-primary-key }} path: | @@ -41,7 +41,7 @@ runs: ~/.asdf/shims - name: Restore Bun install cache - uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 with: key: bun-install-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('bun.lock') }} path: ~/.bun/install/cache diff --git a/.github/actions/fetch-release-secrets/action.yml b/.github/actions/fetch-release-secrets/action.yml index 02f120c..d6c3c51 100644 --- a/.github/actions/fetch-release-secrets/action.yml +++ b/.github/actions/fetch-release-secrets/action.yml @@ -22,7 +22,7 @@ runs: using: 'composite' steps: - name: Configure AWS Credentials - uses: aws-actions/configure-aws-credentials@d979d5b3a71173a29b74b5b88418bfda9437d885 # v6.1.1 + uses: aws-actions/configure-aws-credentials@cbe3b392738ccf3f987d68400dafcf4b0624a56c # v6.2.4 with: role-to-assume: ${{ inputs.role-to-assume }} aws-region: ${{ inputs.aws-region }} diff --git a/.github/workflows/chromatic.yml b/.github/workflows/chromatic.yml index cf4283e..93d431d 100644 --- a/.github/workflows/chromatic.yml +++ b/.github/workflows/chromatic.yml @@ -29,7 +29,7 @@ jobs: timeout-minutes: 10 steps: - name: Checkout code - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 # Chromatic needs full git history to find baselines persist-credentials: false diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index aa78cdb..92a243a 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -23,7 +23,7 @@ jobs: id-token: write # OIDC: assume the AWS release role for signing secrets + sign provenance attestations: write # publish Sigstore build-provenance attestations for the artifacts steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 persist-credentials: false @@ -49,7 +49,7 @@ jobs: done - name: Run GoReleaser - uses: goreleaser/goreleaser-action@1a80836c5c9d9e5755a25cb59ec6f45a3b5f41a8 # v7.2.1 + uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7.2.3 with: version: '~> v2' args: release --clean @@ -62,7 +62,7 @@ jobs: # workflow run, recorded in a public transparency log. Verify a download # with: gh attestation verify --repo contextbridge/patchwave-analysis - name: Attest build provenance - uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0 + uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2 with: subject-checksums: dist-release/checksums.txt @@ -79,7 +79,7 @@ jobs: id-token: write # OIDC: assume the release role to publish the Slack alert steps: - name: Configure AWS credentials - uses: aws-actions/configure-aws-credentials@d979d5b3a71173a29b74b5b88418bfda9437d885 # v6.1.1 + uses: aws-actions/configure-aws-credentials@cbe3b392738ccf3f987d68400dafcf4b0624a56c # v6.2.4 with: role-to-assume: ${{ secrets.RELEASE_ROLE_ARN }} aws-region: us-west-2 diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 25024ac..67f6b71 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -9,14 +9,14 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 10 steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - uses: $/.github/actions/bootstrap - name: Check formatting run: bun run format:check - name: Restore ESLint cache - uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 with: path: .eslintcache key: eslint-${{ runner.os }}-${{ github.sha }} @@ -39,7 +39,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 10 steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - uses: $/.github/actions/bootstrap @@ -50,7 +50,7 @@ jobs: id: ubuntu-version run: echo "version=$(lsb_release -rs)" >> "$GITHUB_OUTPUT" - name: Cache Playwright browsers - uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 with: path: /home/runner/.cache/ms-playwright key: ${{ runner.os }}-${{ steps.ubuntu-version.outputs.version }}-playwright-browsers-${{ steps.playwright-version.outputs.version }} diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml index f31b0c1..27f58ac 100644 --- a/.github/workflows/zizmor.yml +++ b/.github/workflows/zizmor.yml @@ -23,7 +23,7 @@ jobs: # paths-filter needs a git checkout — it runs `git branch --show-current` # before any API fallback, and fails outside a working tree. - name: Checkout - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false @@ -32,7 +32,7 @@ jobs: # API-heavy audit (and SARIF upload) on unrelated PRs. - name: Detect workflow changes id: changes - uses: dorny/paths-filter@fbd0ab8f3e69293af611ebaee6363fc25e6d187d # v4.0.1 + uses: dorny/paths-filter@ceb8a2b8f2d89434be7ff52d3de7ec3738c5cc9d # v4.0.3 with: token: ${{ secrets.GITHUB_TOKEN }} filters: | @@ -42,7 +42,7 @@ jobs: - name: Install uv if: steps.changes.outputs.github == 'true' - uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0 + uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 - name: Run zizmor if: steps.changes.outputs.github == 'true' @@ -52,7 +52,7 @@ jobs: - name: Upload zizmor SARIF to code scanning if: steps.changes.outputs.github == 'true' - uses: github/codeql-action/upload-sarif@9e0d7b8d25671d64c341c19c0152d693099fb5ba # v4.35.5 + uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 with: sarif_file: zizmor.sarif category: zizmor