Skip to content

Commit 2baf2d2

Browse files
authored
chore: pin actions to sha (supabase#592)
1 parent dd6710b commit 2baf2d2

6 files changed

Lines changed: 26 additions & 24 deletions

File tree

.github/workflows/coverage.yml

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -25,16 +25,18 @@ jobs:
2525
runs-on: blacksmith-4vcpu-ubuntu-2404
2626
steps:
2727
- name: Checkout code
28-
uses: actions/checkout@v6
28+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
2929

3030
- name: Install Rust toolchain
31-
uses: actions-rust-lang/setup-rust-toolchain@v1
31+
uses: actions-rust-lang/setup-rust-toolchain@150fca883cd4034361b621bd4e6a9d34e5143606 # v1.15.4
3232
with:
3333
toolchain: 1.88.0
3434
components: llvm-tools-preview, rustfmt, clippy
3535

3636
- name: Install cargo-llvm-cov
37-
uses: taiki-e/install-action@cargo-llvm-cov
37+
uses: taiki-e/install-action@80a23c5ba9e1100fd8b777106e810018ed662a7b # v2.69.12
38+
with:
39+
tool: cargo-llvm-cov
3840

3941
- run: |
4042
sudo apt remove -y postgres*
@@ -67,7 +69,7 @@ jobs:
6769
cargo llvm-cov report --lcov --output-path lcov.info
6870
6971
- name: Coveralls upload
70-
uses: coverallsapp/github-action@v2
72+
uses: coverallsapp/github-action@5cbfd81b66ca5d10c19b062c04de0199c215fb6e # v2.3.7
7173
with:
7274
github-token: ${{ secrets.GITHUB_TOKEN }}
7375
path-to-lcov: lcov.info

.github/workflows/release.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -18,8 +18,8 @@ jobs:
1818
permissions:
1919
id-token: write
2020
steps:
21-
- uses: actions/checkout@v6
22-
- uses: actions-rust-lang/setup-rust-toolchain@v1
21+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
22+
- uses: actions-rust-lang/setup-rust-toolchain@150fca883cd4034361b621bd4e6a9d34e5143606 # v1.15.4
2323
with:
2424
toolchain: 1.88.0
2525

@@ -38,7 +38,7 @@ jobs:
3838
- run: cargo install --locked cargo-pgrx --version 0.16.1
3939
- run: cargo pgrx init --pg15 /usr/lib/postgresql/15/bin/pg_config
4040

41-
- uses: rust-lang/crates-io-auth-action@v1
41+
- uses: rust-lang/crates-io-auth-action@b7e9a28eded4986ec6b1fa40eeee8f8f165559ec # v1.0.3
4242
id: auth
4343

4444
- name: Check and publish supabase-wrappers-macros
@@ -74,7 +74,7 @@ jobs:
7474
runs-on: ubuntu-latest
7575
steps:
7676
- name: Checkout code
77-
uses: actions/checkout@v6
77+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
7878
- name: Create Release
7979
id: create_release
8080
env:
@@ -106,7 +106,7 @@ jobs:
106106
timeout-minutes: 90
107107
steps:
108108
- name: checkout code
109-
uses: actions/checkout@v6
109+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
110110
with:
111111
fetch-depth: 0
112112

@@ -224,7 +224,7 @@ jobs:
224224
run: echo UPLOAD_URL=$(curl --silent https://api.github.com/repos/${{ github.repository }}/releases/latest | jq .upload_url --raw-output) >> $GITHUB_ENV
225225

226226
- name: Upload release asset
227-
uses: actions/upload-release-asset@v1
227+
uses: actions/upload-release-asset@e8f9f06c4b078e705bd2ea027f0926603fc9b4d5 # v1.0.2
228228
env:
229229
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
230230
with:

.github/workflows/release_wasm_fdw.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ jobs:
1414
runs-on: blacksmith-4vcpu-ubuntu-2404
1515
steps:
1616
- name: Checkout code
17-
uses: actions/checkout@v6
17+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
1818

1919
- name: Extract project and version from tag
2020
id: extract_info
@@ -52,7 +52,7 @@ jobs:
5252
cargo component build --release --target wasm32-unknown-unknown
5353
5454
- name: Calculate Wasm file checksum
55-
uses: jmgilman/actions-generate-checksum@v1
55+
uses: jmgilman/actions-generate-checksum@238073f4c02f2810adb91c96bdd1e276a5ae9ed6 # v1
5656
with:
5757
method: sha256
5858
output: wasm-wrappers/fdw/${{ steps.extract_info.outputs.PROJECT }}/checksum.txt
@@ -109,7 +109,7 @@ jobs:
109109
110110
- name: Create release
111111
id: create_release
112-
uses: softprops/action-gh-release@v2
112+
uses: softprops/action-gh-release@153bb8e04406b158c6c84fc1615b65b24149a1fe # v2.6.1
113113
with:
114114
generate_release_notes: true
115115
make_latest: true

.github/workflows/test_docs.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -22,9 +22,9 @@ jobs:
2222
name: Build MkDocs
2323
runs-on: ubuntu-latest
2424
steps:
25-
- uses: actions/checkout@v6
25+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
2626

27-
- uses: actions/setup-python@v6
27+
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
2828
with:
2929
python-version: "3.x"
3030

.github/workflows/test_supabase_wrappers.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -23,9 +23,9 @@ jobs:
2323

2424
steps:
2525
- name: Checkout code
26-
uses: actions/checkout@v6
26+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
2727

28-
- uses: actions-rust-lang/setup-rust-toolchain@v1
28+
- uses: actions-rust-lang/setup-rust-toolchain@150fca883cd4034361b621bd4e6a9d34e5143606 # v1.15.4
2929
with:
3030
toolchain: 1.88.0
3131
components: rustfmt, clippy

.github/workflows/test_wrappers.yml

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ jobs:
1919
native: ${{ steps.filter.outputs.native }}
2020
wasm: ${{ steps.filter.outputs.wasm }}
2121
steps:
22-
- uses: actions/checkout@v6
22+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
2323
with:
2424
fetch-depth: 0
2525
- id: filter
@@ -52,13 +52,13 @@ jobs:
5252

5353
steps:
5454
- name: Checkout code
55-
uses: actions/checkout@v6
55+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
5656

5757
- name: Build docker images
5858
run: |
5959
docker compose -f wrappers/.ci/docker-compose-native.yaml up -d
6060
61-
- uses: actions-rust-lang/setup-rust-toolchain@v1
61+
- uses: actions-rust-lang/setup-rust-toolchain@150fca883cd4034361b621bd4e6a9d34e5143606 # v1.15.4
6262
with:
6363
toolchain: 1.88.0
6464
components: rustfmt, clippy
@@ -100,13 +100,13 @@ jobs:
100100

101101
steps:
102102
- name: Checkout code
103-
uses: actions/checkout@v6
103+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
104104

105105
- name: Build docker images
106106
run: |
107107
docker compose -f wrappers/.ci/docker-compose-wasm.yaml up -d
108108
109-
- uses: actions-rust-lang/setup-rust-toolchain@v1
109+
- uses: actions-rust-lang/setup-rust-toolchain@150fca883cd4034361b621bd4e6a9d34e5143606 # v1.15.4
110110
with:
111111
toolchain: 1.88.0
112112
components: rustfmt, clippy
@@ -156,11 +156,11 @@ jobs:
156156

157157
steps:
158158
- name: Checkout code
159-
uses: actions/checkout@v6
159+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
160160
with:
161161
fetch-depth: 0
162162

163-
- uses: actions-rust-lang/setup-rust-toolchain@v1
163+
- uses: actions-rust-lang/setup-rust-toolchain@150fca883cd4034361b621bd4e6a9d34e5143606 # v1.15.4
164164
with:
165165
toolchain: 1.88.0
166166

0 commit comments

Comments
 (0)