Skip to content

Commit 4ba888b

Browse files
authored
Pin all gh actions to SHAs (#138)
1 parent 242863d commit 4ba888b

File tree

5 files changed

+13
-13
lines changed

5 files changed

+13
-13
lines changed

.github/workflows/build.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -79,12 +79,12 @@ jobs:
7979
file: ${{ fromJson(needs.prepare.outputs.files) }}
8080
steps:
8181
- name: Checkout code
82-
uses: actions/[email protected]
82+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
8383
- name: Replace project version
8484
run: |
8585
sed -i "s/version: dev/version: ${{ needs.prepare.outputs.version }}/g" ${{ matrix.file }}
8686
- name: Build Firmware
87-
uses: esphome/[email protected]
87+
uses: esphome/build-action@76cd6898550762b189215bbe6e50e29080fd2c33 # v7.0.0
8888
id: esphome-build
8989
with:
9090
yaml-file: ${{ matrix.file }}
@@ -97,7 +97,7 @@ jobs:
9797
mkdir -p output/${{ needs.prepare.outputs.version }}
9898
mv ${{ steps.esphome-build.outputs.name }}/* output/${{ needs.prepare.outputs.version }}/
9999
- name: Upload artifact
100-
uses: actions/[email protected]
100+
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
101101
with:
102102
# yamllint disable-line rule:line-length
103103
name: ${{ inputs.combined-name != '' && format('{0}-{1}', needs.prepare.outputs.artifact-prefix, steps.esphome-build.outputs.name) || steps.esphome-build.outputs.original-name }}
@@ -112,7 +112,7 @@ jobs:
112112
if: inputs.combined-name != ''
113113
steps:
114114
- name: Download artifacts
115-
uses: actions/[email protected]
115+
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
116116
with:
117117
path: files
118118
pattern: ${{ needs.prepare.outputs.artifact-prefix }}-*
@@ -126,7 +126,7 @@ jobs:
126126
echo "EOF" >> $GITHUB_OUTPUT
127127
128128
- name: Delete prefixed artifacts
129-
uses: geekyeggo/[email protected]
129+
uses: geekyeggo/delete-artifact@f275313e70c08f6120db482d7a6b98377786765b # v5.1.0
130130
with:
131131
name: ${{ steps.artifacts.outputs.artifacts }}
132132

@@ -147,7 +147,7 @@ jobs:
147147
files/*/$version/manifest.json > output/$version/manifest.json
148148
149149
- name: Upload artifact
150-
uses: actions/[email protected]
150+
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
151151
with:
152152
name: ${{ inputs.combined-name }}
153153
path: output

.github/workflows/lock.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -43,7 +43,7 @@ jobs:
4343
runs-on: ubuntu-latest
4444
steps:
4545
- name: Lock closed issues and PRs
46-
uses: actions/[email protected]
46+
uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0
4747
with:
4848
script: |
4949
const PR_CLOSE_DAYS = ${{ inputs.pr-close-days }};

.github/workflows/promote-r2.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,7 @@ jobs:
2929
environment: ${{ inputs.channel }}
3030
steps:
3131
- name: Download artifacts
32-
uses: actions/[email protected]
32+
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
3333
with:
3434
path: files
3535

@@ -47,7 +47,7 @@ jobs:
4747
done
4848
4949
- name: Upload ${{ inputs.manifest-filename }} to R2
50-
uses: ryand56/[email protected]
50+
uses: ryand56/r2-upload-action@b801a390acbdeb034c5e684ff5e1361c06639e7c # v1.4
5151
with:
5252
r2-account-id: ${{ secrets.CLOUDFLARE_R2_ACCOUNT_ID }}
5353
r2-access-key-id: ${{ secrets.CLOUDFLARE_R2_ACCESS_KEY_ID }}

.github/workflows/upload-to-gh-release.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@ jobs:
1616
contents: write
1717
steps:
1818
- name: Download Artifact
19-
uses: actions/[email protected]
19+
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
2020
with:
2121
path: files
2222

@@ -52,7 +52,7 @@ jobs:
5252
popd
5353
5454
- name: Upload files to release
55-
uses: softprops/[email protected]
55+
uses: softprops/action-gh-release@6cbd405e2c4e67a21c47fa9e383d020e4e28b836 # v2.3.3
5656
with:
5757
files: output/*
5858
tag_name: ${{ inputs.version }}

.github/workflows/upload-to-r2.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,14 +17,14 @@ jobs:
1717
runs-on: ubuntu-latest
1818
steps:
1919
- name: Download artifacts
20-
uses: actions/[email protected]
20+
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
2121
with:
2222
path: files
2323

2424
- run: tree
2525

2626
- name: Upload files to R2
27-
uses: ryand56/[email protected]
27+
uses: ryand56/r2-upload-action@b801a390acbdeb034c5e684ff5e1361c06639e7c # v1.4
2828
with:
2929
r2-account-id: ${{ secrets.CLOUDFLARE_R2_ACCOUNT_ID }}
3030
r2-access-key-id: ${{ secrets.CLOUDFLARE_R2_ACCESS_KEY_ID }}

0 commit comments

Comments
 (0)