From 0824a2ac7babcbb6bcce676405ce8a368674358f Mon Sep 17 00:00:00 2001 From: "renovate-pagopa[bot]" <164534245+renovate-pagopa[bot]@users.noreply.github.com> Date: Mon, 7 Oct 2024 05:40:41 +0000 Subject: [PATCH] Pin dependencies --- .github/actions/build-nextjs-website/action.yaml | 2 +- .github/actions/deploy/action.yaml | 2 +- .github/workflows/move_latest_tag.yaml | 2 +- apps/chatbot/docker/app.Dockerfile | 2 +- apps/chatbot/docker/app.local.Dockerfile | 2 +- 5 files changed, 5 insertions(+), 5 deletions(-) diff --git a/.github/actions/build-nextjs-website/action.yaml b/.github/actions/build-nextjs-website/action.yaml index 3f72e40e7..655233b5e 100644 --- a/.github/actions/build-nextjs-website/action.yaml +++ b/.github/actions/build-nextjs-website/action.yaml @@ -54,7 +54,7 @@ runs: using: "composite" steps: - name: Download GitBook docs - uses: actions/checkout@v4 + uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4 with: repository: pagopa/devportal-docs ref: docs/from-gitbook diff --git a/.github/actions/deploy/action.yaml b/.github/actions/deploy/action.yaml index a8faf7817..65830de87 100644 --- a/.github/actions/deploy/action.yaml +++ b/.github/actions/deploy/action.yaml @@ -74,7 +74,7 @@ runs: run: npm run compile - name: Download GitBook docs - uses: actions/checkout@v4 + uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4 with: repository: pagopa/devportal-docs ref: docs/from-gitbook diff --git a/.github/workflows/move_latest_tag.yaml b/.github/workflows/move_latest_tag.yaml index 7bee4f6f8..67cd3e3c0 100644 --- a/.github/workflows/move_latest_tag.yaml +++ b/.github/workflows/move_latest_tag.yaml @@ -12,7 +12,7 @@ jobs: if: ${{ startsWith(github.ref, 'refs/tags/') && !endsWith(github.ref, '@latest') }} steps: - name: Checkout repository - uses: actions/checkout@v4 + uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4 - name: Get commit hash associated with the new tag id: get-commit diff --git a/apps/chatbot/docker/app.Dockerfile b/apps/chatbot/docker/app.Dockerfile index 4e2aae36b..71573be5a 100644 --- a/apps/chatbot/docker/app.Dockerfile +++ b/apps/chatbot/docker/app.Dockerfile @@ -1,4 +1,4 @@ -FROM public.ecr.aws/lambda/python:3.12 +FROM public.ecr.aws/lambda/python:3.12@sha256:f5308d146329323f72af229ad795c1f7433b63953697997bfd9b7fb6871d2b97 ARG DEBIAN_FRONTEND=noninteractive ENV PYTHONPATH=$LAMBDA_TASK_ROOT diff --git a/apps/chatbot/docker/app.local.Dockerfile b/apps/chatbot/docker/app.local.Dockerfile index 21bcd8be8..bfe49f911 100644 --- a/apps/chatbot/docker/app.local.Dockerfile +++ b/apps/chatbot/docker/app.local.Dockerfile @@ -1,4 +1,4 @@ -FROM python:3.12.4-slim-bullseye +FROM python:3.12.4-slim-bullseye@sha256:26ce493641ad3b1c8a6202117c31340c7bbb2dc126f1aeee8ea3972730a81dc6 ARG DEBIAN_FRONTEND=noninteractive ENV PYTHONPATH=/app