diff --git a/.github/workflows/_parse_version.yml b/.github/workflows/_parse_version.yml index f77494e5d31..0b1a8198b6c 100644 --- a/.github/workflows/_parse_version.yml +++ b/.github/workflows/_parse_version.yml @@ -107,7 +107,7 @@ jobs: timeout-minutes: 2 - name: Upload patch - uses: actions/upload-artifact@6f51ac03b9356f520e9adb1b1b7802705f340c2b # pin v4.5.0 + uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # pin v4.6.0 with: name: version.patch path: | diff --git a/.github/workflows/ci-rust.yml b/.github/workflows/ci-rust.yml index 4efad95070a..122898fbf84 100644 --- a/.github/workflows/ci-rust.yml +++ b/.github/workflows/ci-rust.yml @@ -102,7 +102,7 @@ jobs: timeout-minutes: 5 # Install cargo nextest command - - uses: taiki-e/install-action@a86da1a3cb51967612c80d6dc98c5cac03a73025 # pin v2.47.7 + - uses: taiki-e/install-action@c87777c3160ce0cfd8fc286df47224d2449cb76b # pin v2.47.11 with: tool: nextest@0.9.54, wasm-pack@0.12.1, cargo-deny@0.15.0 @@ -263,7 +263,7 @@ jobs: timeout-minutes: 5 # Install cargo nextest command - - uses: taiki-e/install-action@a86da1a3cb51967612c80d6dc98c5cac03a73025 # pin v2.47.7 + - uses: taiki-e/install-action@c87777c3160ce0cfd8fc286df47224d2449cb76b # pin v2.47.11 with: tool: nextest@0.9.54 diff --git a/.github/workflows/ci-web.yml b/.github/workflows/ci-web.yml index f1c48f37a6d..f9a44a95ca8 100644 --- a/.github/workflows/ci-web.yml +++ b/.github/workflows/ci-web.yml @@ -130,7 +130,7 @@ jobs: timeout-minutes: 5 # Install wasm-pack command - - uses: taiki-e/install-action@a86da1a3cb51967612c80d6dc98c5cac03a73025 # pin v2.47.7 + - uses: taiki-e/install-action@c87777c3160ce0cfd8fc286df47224d2449cb76b # pin v2.47.11 with: tool: wasm-pack@${{ env.wasm-pack-version }} @@ -172,7 +172,7 @@ jobs: - name: Archive test results if: failure() - uses: actions/upload-artifact@6f51ac03b9356f520e9adb1b1b7802705f340c2b # pin v4.5.0 + uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # pin v4.6.0 with: name: playwright-artifacts path: client/test-results/ diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 6e64bb5ab03..1cb5d7f517d 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -191,7 +191,7 @@ jobs: diff --unified .pre-commit-config.yaml $TEMP_FILE || true echo "path=$TEMP_FILE" >> $GITHUB_OUTPUT - - uses: taiki-e/install-action@a86da1a3cb51967612c80d6dc98c5cac03a73025 # pin v2.47.7 + - uses: taiki-e/install-action@c87777c3160ce0cfd8fc286df47224d2449cb76b # pin v2.47.11 with: tool: taplo-cli@0.9.3 diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 22508ae145a..471457f1470 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -58,7 +58,7 @@ jobs: # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL if: steps.should-run-python-analysis.outputs.run == 'true' - uses: github/codeql-action/init@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 # pin v3.28.0 + uses: github/codeql-action/init@b6a472f63d85b9c78a3ac5e89422239fc15e9b3c # pin v3.28.1 with: languages: python setup-python-dependencies: false @@ -87,7 +87,7 @@ jobs: - name: Perform CodeQL Analysis if: steps.should-run-python-analysis.outputs.run == 'true' - uses: github/codeql-action/analyze@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 # pin v3.28.0 + uses: github/codeql-action/analyze@b6a472f63d85b9c78a3ac5e89422239fc15e9b3c # pin v3.28.1 with: category: /language:python @@ -142,7 +142,7 @@ jobs: # # Initializes the CodeQL tools for scanning. # - name: Initialize CodeQL # if: steps.should-run-java-analysis.outputs.run == 'true' - # uses: github/codeql-action/init@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 # pin v3.28.0 + # uses: github/codeql-action/init@b6a472f63d85b9c78a3ac5e89422239fc15e9b3c # pin v3.28.1 # with: # languages: java # # If you wish to specify custom queries, you can do so here or in a config file. @@ -154,7 +154,7 @@ jobs: # - name: Autobuild android # if: steps.should-run-java-analysis.outputs.run == 'true' - # uses: github/codeql-action/autobuild@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 # pin v3.28.0 + # uses: github/codeql-action/autobuild@b6a472f63d85b9c78a3ac5e89422239fc15e9b3c # pin v3.28.1 # with: # working-directory: client/android # env: @@ -162,7 +162,7 @@ jobs: # - name: Perform CodeQL Analysis # if: steps.should-run-java-analysis.outputs.run == 'true' - # uses: github/codeql-action/analyze@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 # pin v3.28.0 + # uses: github/codeql-action/analyze@b6a472f63d85b9c78a3ac5e89422239fc15e9b3c # pin v3.28.1 # with: # category: /language:java @@ -191,7 +191,7 @@ jobs: # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL if: steps.should-run-js-analysis.outputs.run == 'true' - uses: github/codeql-action/init@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 # pin v3.28.0 + uses: github/codeql-action/init@b6a472f63d85b9c78a3ac5e89422239fc15e9b3c # pin v3.28.1 with: languages: typescript @@ -202,12 +202,12 @@ jobs: - name: Autobuild for typescript if: steps.should-run-js-analysis.outputs.run == 'true' - uses: github/codeql-action/autobuild@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 # pin v3.28.0 + uses: github/codeql-action/autobuild@b6a472f63d85b9c78a3ac5e89422239fc15e9b3c # pin v3.28.1 with: working-directory: client - name: Perform CodeQL Analysis if: steps.should-run-js-analysis.outputs.run == 'true' - uses: github/codeql-action/analyze@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 # pin v3.28.0 + uses: github/codeql-action/analyze@b6a472f63d85b9c78a3ac5e89422239fc15e9b3c # pin v3.28.1 with: category: /language:typescript diff --git a/.github/workflows/docker-server.yml b/.github/workflows/docker-server.yml index ce7b6f12165..912623d65d4 100644 --- a/.github/workflows/docker-server.yml +++ b/.github/workflows/docker-server.yml @@ -70,7 +70,7 @@ jobs: latest=${{ github.event_name == 'push' && github.ref_type == 'tag' }} - name: Build and export to Docker - uses: docker/build-push-action@48aba3b46d1b1fec4febb7c5d0c644b249a11355 # v6.10.0 + uses: docker/build-push-action@b32b51a8eda65d6793cd0494a773d4f6bcef32dc # v6.11.0 id: build with: context: . @@ -103,7 +103,7 @@ jobs: run: echo "${{ steps.metadata.outputs.tags }}" - name: Build and publish - uses: docker/build-push-action@48aba3b46d1b1fec4febb7c5d0c644b249a11355 # v6.10.0 + uses: docker/build-push-action@b32b51a8eda65d6793cd0494a773d4f6bcef32dc # v6.11.0 id: publish with: context: . diff --git a/.github/workflows/docker-testbed.yml b/.github/workflows/docker-testbed.yml index 8dd543a864c..0dbad08aad9 100644 --- a/.github/workflows/docker-testbed.yml +++ b/.github/workflows/docker-testbed.yml @@ -77,7 +77,7 @@ jobs: latest=${{ github.event_name == 'workflow_dispatch' }} - name: Build and export to Docker - uses: docker/build-push-action@48aba3b46d1b1fec4febb7c5d0c644b249a11355 # v6.10.0 + uses: docker/build-push-action@b32b51a8eda65d6793cd0494a773d4f6bcef32dc # v6.11.0 id: build with: context: . @@ -111,7 +111,7 @@ jobs: - name: Build and publish if: github.event_name == 'workflow_dispatch' - uses: docker/build-push-action@48aba3b46d1b1fec4febb7c5d0c644b249a11355 # v6.10.0 + uses: docker/build-push-action@b32b51a8eda65d6793cd0494a773d4f6bcef32dc # v6.11.0 with: context: . file: server/packaging/testbed-server/testbed-server.dockerfile diff --git a/.github/workflows/package-cli.yml b/.github/workflows/package-cli.yml index 53fbcc2c3e1..aaa0ed4dfb6 100644 --- a/.github/workflows/package-cli.yml +++ b/.github/workflows/package-cli.yml @@ -132,7 +132,7 @@ jobs: echo "artifact_name=$FINAL_ARTIFACT_NAME" >> $GITHUB_OUTPUT timeout-minutes: 1 - - uses: actions/upload-artifact@6f51ac03b9356f520e9adb1b1b7802705f340c2b # pin v4.5.0 + - uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # pin v4.6.0 with: name: ${{ runner.os }}-${{ matrix.target }}-cli path: | diff --git a/.github/workflows/package-client.yml b/.github/workflows/package-client.yml index e4aa5abb4aa..0809bd16c4d 100644 --- a/.github/workflows/package-client.yml +++ b/.github/workflows/package-client.yml @@ -108,7 +108,7 @@ jobs: working-directory: client # Install syft - - uses: taiki-e/install-action@a86da1a3cb51967612c80d6dc98c5cac03a73025 # pin v2.47.7 + - uses: taiki-e/install-action@c87777c3160ce0cfd8fc286df47224d2449cb76b # pin v2.47.11 with: tool: syft@0.84.0, wasm-pack@${{ env.wasm-pack-version }} @@ -125,7 +125,7 @@ jobs: - name: Generate SBOM run: syft packages --config=.syft.yaml --output=spdx-json=client/dist/Parsec-SBOM-Web.spdx.json . - - uses: actions/upload-artifact@6f51ac03b9356f520e9adb1b1b7802705f340c2b # pin v4.5.0 + - uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # pin v4.6.0 with: name: webapp path: client/dist/ @@ -211,14 +211,14 @@ jobs: mv -v parsec_*_*.snap Parsec_${{ steps.version.outputs.full }}_linux_$ARCH.snap # Install syft - - uses: taiki-e/install-action@a86da1a3cb51967612c80d6dc98c5cac03a73025 # pin v2.47.7 + - uses: taiki-e/install-action@c87777c3160ce0cfd8fc286df47224d2449cb76b # pin v2.47.11 with: tool: syft@0.84.0 - name: Generate SBOM run: syft packages --config=.syft.yaml --output=spdx-json=Parsec-SBOM-Electron-linux-snap.spdx.json . - - uses: actions/upload-artifact@6f51ac03b9356f520e9adb1b1b7802705f340c2b # pin v4.5.0 + - uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # pin v4.6.0 with: name: linux-snap-${{ runner.arch }}-electron path: | @@ -404,7 +404,7 @@ jobs: timeout-minutes: 1 # Install syft - - uses: taiki-e/install-action@a86da1a3cb51967612c80d6dc98c5cac03a73025 # pin v2.47.7 + - uses: taiki-e/install-action@c87777c3160ce0cfd8fc286df47224d2449cb76b # pin v2.47.11 with: tool: syft@0.84.0 @@ -441,7 +441,7 @@ jobs: grep -q -e "${{ steps.build-info.outputs.app_file }}" "${{ steps.build-info.outputs.latest_file }}" working-directory: client/electron/dist - - uses: actions/upload-artifact@6f51ac03b9356f520e9adb1b1b7802705f340c2b # pin v4.5.0 + - uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # pin v4.6.0 with: name: ${{ matrix.artifact_tag }}-${{ runner.arch }}-electron path: | @@ -452,7 +452,7 @@ jobs: if-no-files-found: error timeout-minutes: 10 - - uses: actions/upload-artifact@6f51ac03b9356f520e9adb1b1b7802705f340c2b # pin v4.5.0 + - uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # pin v4.6.0 if: matrix.platform == 'windows' with: name: ${{ matrix.artifact_tag }}-${{ runner.arch }}-electron-pre-built diff --git a/.github/workflows/package-server.yml b/.github/workflows/package-server.yml index 66b6348a20e..d2a19bce9e3 100644 --- a/.github/workflows/package-server.yml +++ b/.github/workflows/package-server.yml @@ -111,14 +111,14 @@ jobs: run: python server/packaging/wheel/wheel_it.py ./server --output dist --skip-wheel # Install syft - - uses: taiki-e/install-action@a86da1a3cb51967612c80d6dc98c5cac03a73025 # pin v2.47.7 + - uses: taiki-e/install-action@c87777c3160ce0cfd8fc286df47224d2449cb76b # pin v2.47.11 with: tool: syft@0.84.0 - name: Generate SBOM run: syft packages --config=.syft.yaml --output=spdx-json=dist/Parsec-SBOM-Wheel-${{ matrix.platform }}.spdx.json . - - uses: actions/upload-artifact@6f51ac03b9356f520e9adb1b1b7802705f340c2b # pin v4.5.0 + - uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # pin v4.6.0 with: name: ${{ runner.os }}-${{ runner.arch }}-wheel path: |