Skip to content

Commit 327763e

Browse files
authored
Merge pull request #3 from JohT/renovate/pin-dependencies
Pin dependencies
2 parents 06e416b + 1292e5f commit 327763e

File tree

5 files changed

+24
-24
lines changed

5 files changed

+24
-24
lines changed

.github/workflows/analyze-code-graph.yml

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -49,22 +49,22 @@ jobs:
4949
if: inputs.artifacts-upload-name == '' && inputs.sources-upload-name == ''
5050
run: echo "Please specify either the input parameter 'artifacts-upload-name' or 'sources-upload-name'."; exit 1
5151
- name: Checkout code-graph-analysis-pipeline
52-
uses: actions/checkout@v4
52+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
5353
with:
5454
repository: JohT/code-graph-analysis-pipeline
5555
ref: 41f3e22b5bd65351474dd23effeee91fab849a12
5656
path: code-graph-analysis-pipeline
5757
persist-credentials: false
5858

5959
- name: (Java Setup) Java Development Kit (JDK) ${{ matrix.java }}
60-
uses: actions/setup-java@v4
60+
uses: actions/setup-java@7a6d8a8234af8eb26422e24e3006232cccaa061b # v4
6161
with:
6262
distribution: "temurin"
6363
java-version: ${{ matrix.java }}
6464

6565
# "Setup Python" can be skipped if jupyter notebook analysis-results aren't needed
6666
- name: (Python Setup) Setup Cache for Conda package manager Miniforge
67-
uses: actions/cache@v4
67+
uses: actions/cache@1bd1e32a3bdc45362d1e726936510720a7c30a57 # v4
6868
env:
6969
# Increase this value to reset cache if etc/example-environment.yml has not changed
7070
# Reference: https://github.com/conda-incubator/setup-miniconda#caching
@@ -75,7 +75,7 @@ jobs:
7575
${{ runner.os }}-conda-${{ env.CACHE_NUMBER }}-environments-${{hashFiles('**/environment.yml', '.github/workflows/*.yml') }}
7676

7777
- name: (Python Setup) Use version ${{ matrix.python }} with Conda package manager Miniforge
78-
uses: conda-incubator/setup-miniconda@v3
78+
uses: conda-incubator/setup-miniconda@d2e6a045a86077fb6cad6f5adf368e9076ddaa8d # v3
7979
with:
8080
python-version: ${{ matrix.python }}
8181
miniforge-version: ${{ matrix.miniforge }}
@@ -95,7 +95,7 @@ jobs:
9595
echo "code-graph-analysis-pipeline/" >> .gitignore
9696
9797
- name: (Code Analysis Setup) Setup Cache Analysis Downloads
98-
uses: actions/cache@v4
98+
uses: actions/cache@1bd1e32a3bdc45362d1e726936510720a7c30a57 # v4
9999
with:
100100
path: ./code-graph-analysis-pipeline/temp/downloads
101101
key:
@@ -118,14 +118,14 @@ jobs:
118118

119119
- name: (Code Analysis Setup) Download sources for analysis
120120
if: inputs.sources-upload-name != ''
121-
uses: actions/download-artifact@v4
121+
uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4
122122
with:
123123
name: ${{ inputs.sources-upload-name }}
124124
path: code-graph-analysis-pipeline/temp/${{ inputs.analysis-name }}/source/${{ inputs.analysis-name }}
125125

126126
- name: (Code Analysis Setup) Download artifacts for analysis
127127
if: inputs.artifacts-upload-name != ''
128-
uses: actions/download-artifact@v4
128+
uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4
129129
with:
130130
name: ${{ inputs.artifacts-upload-name }}
131131
path: code-graph-analysis-pipeline/temp/${{ inputs.analysis-name }}/artifacts
@@ -151,7 +151,7 @@ jobs:
151151
# Upload logs and unfinished analysis-results in case of an error for troubleshooting
152152
- name: (Code Analysis Results) Archive failed run with logs and unfinished analysis-results
153153
if: failure()
154-
uses: actions/upload-artifact@v4
154+
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4
155155
with:
156156
name: java-code-analysis-logs-java-${{ matrix.java }}-python-${{ matrix.python }}-miniforge-${{ matrix.miniforge }}
157157
path: |
@@ -162,7 +162,7 @@ jobs:
162162
# Upload successful analysis-results in case they are needed for troubleshooting
163163
- name: (Code Analysis Results) Archive successful analysis-results
164164
if: success()
165-
uses: actions/upload-artifact@v4
165+
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4
166166
with:
167167
name: ${{ steps.set-analysis-results-artifact-name.outputs.uploaded-analysis-results-artifact-name }}
168168
path: ./code-graph-analysis-pipeline/temp/${{ inputs.analysis-name }}/reports/*

.github/workflows/check-links-in-documentation.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -16,10 +16,10 @@ jobs:
1616
runs-on: ubuntu-latest
1717
steps:
1818
- name: Checkout GIT Repository
19-
uses: actions/checkout@v4
19+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
2020

2121
- name: Setup node.js
22-
uses: actions/setup-node@v4
22+
uses: actions/setup-node@39370e3970a6d050c480ffad4ff0ed4d3fdee5af # v4
2323
with:
2424
node-version-file: '.nvmrc'
2525

.github/workflows/check-renovate-config.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -13,10 +13,10 @@ jobs:
1313
runs-on: ubuntu-latest
1414
steps:
1515
- name: Checkout GIT Repository
16-
uses: actions/checkout@v4
16+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
1717

1818
- name: Setup node.js
19-
uses: actions/setup-node@v4
19+
uses: actions/setup-node@39370e3970a6d050c480ffad4ff0ed4d3fdee5af # v4
2020
with:
2121
node-version-file: '.nvmrc'
2222

.github/workflows/java-code-analysis.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -53,14 +53,14 @@ jobs:
5353

5454
steps:
5555
- name: (Prepare Code to Analyze) Checkout AxonFramework repository
56-
uses: actions/checkout@v4
56+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
5757
with:
5858
repository: AxonFramework/AxonFramework
5959
ref: axon-${{ env.AXON_FRAMEWORK_VERSION }}
6060
path: ./source
6161

6262
- name: (Prepare Code to Analyze) Setup Java Development Kit for Maven JARs downloading (JDK) ${{ env.JAVA_VERSION}}
63-
uses: actions/setup-java@v4
63+
uses: actions/setup-java@7a6d8a8234af8eb26422e24e3006232cccaa061b # v4
6464
with:
6565
distribution: "temurin"
6666
java-version: ${{ env.JAVA_VERSION}}
@@ -94,7 +94,7 @@ jobs:
9494

9595
- name: (Prepare Code to Analyze) Upload sources to analyze
9696
if: success()
97-
uses: actions/upload-artifact@v4
97+
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4
9898
with:
9999
name: ${{ steps.set-sources-upload-name.outputs.sources-upload-name }}
100100
path: ./source
@@ -103,7 +103,7 @@ jobs:
103103

104104
- name: (Prepare Code to Analyze) Upload artifacts to analyze
105105
if: success()
106-
uses: actions/upload-artifact@v4
106+
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4
107107
with:
108108
name: ${{ steps.set-artifacts-upload-name.outputs.artifacts-upload-name }}
109109
path: ./artifacts
@@ -130,12 +130,12 @@ jobs:
130130

131131
steps:
132132
- name: Checkout GIT Repository
133-
uses: actions/checkout@v4
133+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
134134
with:
135135
token: ${{ secrets.WORKFLOW_GIT_ACCESS_TOKEN }}
136136

137137
- name: (Code Analysis Setup) Download source code and artifacts for analysis
138-
uses: actions/download-artifact@v4
138+
uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4
139139
with:
140140
name: ${{ needs.analyze-code-graph.outputs.uploaded-analysis-results }}
141141
path: analysis-results/${{ needs.prepare-code-to-analyze.outputs.analysis-name }}

.github/workflows/typescript-code-analysis.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -50,13 +50,13 @@ jobs:
5050

5151
steps:
5252
- name: (Prepare Code to Analyze) Checkout react-router repository
53-
uses: actions/checkout@v4
53+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
5454
with:
5555
repository: remix-run/react-router
5656
ref: react-router@${{ env.REACT_ROUTER_VERSION }}
5757

5858
- name: (Prepare Code to Analyze) Setup pnpm for react-router
59-
uses: pnpm/[email protected]
59+
uses: pnpm/action-setup@fe02b34f77f8bc703788d5817da081398fad5dd2 # v4.0.0
6060

6161
- name: (Prepare Code to Analyze) Install dependencies with pnpm
6262
run: pnpm install --frozen-lockfile --strict-peer-dependencies
@@ -75,7 +75,7 @@ jobs:
7575

7676
- name: (Prepare Code to Analyze) Upload code to analyze
7777
if: success()
78-
uses: actions/upload-artifact@v4
78+
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4
7979
with:
8080
name: ${{ steps.set-sources-upload-name.outputs.sources-upload-name }}
8181
path: .
@@ -101,12 +101,12 @@ jobs:
101101

102102
steps:
103103
- name: Checkout GIT Repository
104-
uses: actions/checkout@v4
104+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
105105
with:
106106
token: ${{ secrets.WORKFLOW_GIT_ACCESS_TOKEN }}
107107

108108
- name: (Code Analysis Setup) Download source code and artifacts for analysis
109-
uses: actions/download-artifact@v4
109+
uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4
110110
with:
111111
name: ${{ needs.analyze-code-graph.outputs.uploaded-analysis-results }}
112112
path: analysis-results/${{ needs.prepare-code-to-analyze.outputs.analysis-name }}

0 commit comments

Comments
 (0)