diff --git a/.github/workflows/bump-neuvector.yaml b/.github/workflows/bump-neuvector.yaml index 98d2bde4..767d40f8 100644 --- a/.github/workflows/bump-neuvector.yaml +++ b/.github/workflows/bump-neuvector.yaml @@ -12,10 +12,10 @@ jobs: pull-requests: write # for updatecli to create a PR steps: - name: Checkout - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 + uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1 - name: Install Updatecli in the runner - uses: updatecli/updatecli-action@57aa8966d4d775cb1420b90c270ba97a4b5abe47 # v2.93.0 + uses: updatecli/updatecli-action@b846825b298f5351abd80f94c4f9eab63a38a804 # v2.98.0 - name: Update neuvector dependency env: diff --git a/.github/workflows/bump-sigstore.yaml b/.github/workflows/bump-sigstore.yaml index 11423638..9fedeb2b 100644 --- a/.github/workflows/bump-sigstore.yaml +++ b/.github/workflows/bump-sigstore.yaml @@ -12,10 +12,10 @@ jobs: pull-requests: write # for updatecli to create a PR steps: - name: Checkout - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 + uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1 - name: Install Updatecli in the runner - uses: updatecli/updatecli-action@57aa8966d4d775cb1420b90c270ba97a4b5abe47 # v2.93.0 + uses: updatecli/updatecli-action@b846825b298f5351abd80f94c4f9eab63a38a804 # v2.98.0 - name: Update sigstore-interface dependency env: diff --git a/.github/workflows/golangci-lint.yml b/.github/workflows/golangci-lint.yml index 0e70276b..e705514d 100644 --- a/.github/workflows/golangci-lint.yml +++ b/.github/workflows/golangci-lint.yml @@ -12,10 +12,10 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 with: fetch-depth: 0 - - uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5.5.0 + - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.6.0 with: go-version: stable - name: golangci-lint diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index a820c194..5779c728 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -18,7 +18,7 @@ jobs: steps: - name: Checkout code - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 + uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 - name: Load Secrets from Vault uses: rancher-eio/read-vault-secrets@main with: @@ -79,7 +79,7 @@ jobs: id-token: write steps: - name: Checkout code - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 + uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 - name: Load Secrets from Vault uses: rancher-eio/read-vault-secrets@main with: @@ -103,7 +103,7 @@ jobs: fi - name: Login to registry if: env.UPDATE_MUTABLE_TAG == 'True' - uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3 + uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3 with: registry: docker.io username: ${{ env.DOCKER_USERNAME }} @@ -114,7 +114,7 @@ jobs: docker buildx imagetools create --tag docker.io/${{ github.repository_owner }}/scanner:6 docker.io/${{ github.repository_owner }}/scanner:${TAG} - name: Login to registry if: env.UPDATE_MUTABLE_TAG == 'True' - uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3 + uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3 with: registry: ${{ env.PRIME_REGISTRY }} username: ${{ env.PRIME_REGISTRY_USERNAME }} @@ -125,7 +125,7 @@ jobs: docker buildx imagetools create --tag ${PRIME_REGISTRY}/rancher/neuvector-scanner:6 ${PRIME_REGISTRY}/rancher/neuvector-scanner:${TAG} - name: Login to registry if: env.UPDATE_MUTABLE_TAG == 'True' - uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3 + uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3 with: registry: docker.io username: ${{ env.RANCHER_DOCKER_USERNAME }} diff --git a/.github/workflows/unitest.yaml b/.github/workflows/unitest.yaml index 2f049391..fc90dd12 100644 --- a/.github/workflows/unitest.yaml +++ b/.github/workflows/unitest.yaml @@ -8,8 +8,8 @@ jobs: unitest: runs-on: ubuntu-latest steps: - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 - - uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5 + - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 + - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 with: go-version: '1.24.5' - run: |