diff --git a/.github/workflows/_build-cerebro-binaries.yml b/.github/workflows/_build-cerebro-binaries.yml index faa6e06d..186d1b5f 100644 --- a/.github/workflows/_build-cerebro-binaries.yml +++ b/.github/workflows/_build-cerebro-binaries.yml @@ -37,7 +37,7 @@ jobs: steps: - name: โœˆ Checkout repository - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 1 @@ -63,7 +63,7 @@ jobs: output.write(f"channel={channel}\n") - name: ๐Ÿฆ€ Setup Rust toolchain - uses: dtolnay/rust-toolchain@f7ccc83f9ed1e5b9c81d8a67d7ad1a747e22a561 + uses: dtolnay/rust-toolchain@d1031067263f94b142dd6c0ce24c5eb9d02d52a0 with: toolchain: ${{ steps.rust-channel.outputs.channel }} targets: ${{ matrix.target }} @@ -252,7 +252,7 @@ jobs: Compress-Archive -Path "clients/cerebro/dist/${{ matrix.artifact_name }}.exe" -DestinationPath "clients/cerebro/dist/${{ matrix.artifact_name }}.zip" -Force - name: โฌ† Upload release artifact - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: ${{ matrix.artifact_name }} path: clients/cerebro/dist/${{ matrix.artifact_name }}.${{ matrix.archive_ext }} diff --git a/.github/workflows/_build-native-binaries.yml b/.github/workflows/_build-native-binaries.yml index 25011bff..afdfb4a1 100644 --- a/.github/workflows/_build-native-binaries.yml +++ b/.github/workflows/_build-native-binaries.yml @@ -38,7 +38,7 @@ jobs: steps: - name: โœˆ Checkout repository - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 1 @@ -64,7 +64,7 @@ jobs: output.write(f"channel={channel}\n") - name: ๐Ÿฆ€ Setup Rust toolchain - uses: dtolnay/rust-toolchain@f7ccc83f9ed1e5b9c81d8a67d7ad1a747e22a561 + uses: dtolnay/rust-toolchain@d1031067263f94b142dd6c0ce24c5eb9d02d52a0 with: toolchain: ${{ steps.rust-channel.outputs.channel }} targets: ${{ matrix.target }} @@ -104,7 +104,7 @@ jobs: Compress-Archive -Path "clients/agent-runtime/dist/${{ matrix.artifact_name }}.exe" -DestinationPath "clients/agent-runtime/dist/${{ matrix.artifact_name }}.zip" -Force - name: โฌ† Upload release artifact - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: ${{ matrix.artifact_name }} path: clients/agent-runtime/dist/${{ matrix.artifact_name }}.${{ matrix.archive_ext }} diff --git a/.github/workflows/_build-rook-binaries.yml b/.github/workflows/_build-rook-binaries.yml index bd4b9faa..0d3a373d 100644 --- a/.github/workflows/_build-rook-binaries.yml +++ b/.github/workflows/_build-rook-binaries.yml @@ -37,7 +37,7 @@ jobs: steps: - name: โœˆ Checkout repository - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 1 @@ -63,7 +63,7 @@ jobs: output.write(f"channel={channel}\n") - name: ๐Ÿฆ€ Setup Rust toolchain - uses: dtolnay/rust-toolchain@f7ccc83f9ed1e5b9c81d8a67d7ad1a747e22a561 + uses: dtolnay/rust-toolchain@d1031067263f94b142dd6c0ce24c5eb9d02d52a0 with: toolchain: ${{ steps.rust-channel.outputs.channel }} targets: ${{ matrix.target }} @@ -96,7 +96,7 @@ jobs: Compress-Archive -Path "clients/rook/dist/${{ matrix.artifact_name }}.exe" -DestinationPath "clients/rook/dist/${{ matrix.artifact_name }}.zip" -Force - name: โฌ† Upload release artifact - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: ${{ matrix.artifact_name }} path: clients/rook/dist/${{ matrix.artifact_name }}.${{ matrix.archive_ext }} diff --git a/.github/workflows/_publish.yml b/.github/workflows/_publish.yml index b98d0f62..c8e19548 100644 --- a/.github/workflows/_publish.yml +++ b/.github/workflows/_publish.yml @@ -59,7 +59,7 @@ jobs: steps: - name: โœˆ Checkout repository - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 @@ -153,13 +153,13 @@ jobs: cargo --version - name: โ˜• Setup Java - uses: actions/setup-java@be666c2fcd27ec809703dec50e508c2fdc7f6654 # v5.2.0 + uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 with: java-version: "25" distribution: "corretto" - name: ๐Ÿ˜ Setup Gradle - uses: gradle/actions/setup-gradle@0723195856401067f7a2779048b490ace7a47d7c # v5.0.2 + uses: gradle/actions/setup-gradle@9c971963bec38e04b3d30dcc455b5382be2fdbfb # v6.3.0 with: gradle-version: wrapper @@ -584,10 +584,10 @@ jobs: packages: write steps: - name: โœˆ Checkout repository - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: โฌ‡ Download Linux artifacts - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: pattern: corvus-linux-* path: clients/agent-runtime/dist @@ -603,20 +603,20 @@ jobs: chmod +x corvus-linux-x64 corvus-linux-arm64 - name: ๐Ÿณ Set up QEMU - uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130 # v3 + uses: docker/setup-qemu-action@1f40c72289eff860ee54a304f1438e3cff362e0a # v4.3.0 - name: ๐Ÿณ Set up Docker Buildx - uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3 + uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0 - name: ๐Ÿ” Login to Docker Hub continue-on-error: true - uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3 + uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 with: username: ${{ secrets.DOCKERHUB_USERNAME }} password: ${{ secrets.DOCKERHUB_TOKEN }} - name: ๐Ÿ” Login to GitHub Container Registry - uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3 + uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 with: registry: ghcr.io username: ${{ github.actor }} @@ -624,7 +624,7 @@ jobs: - name: ๐Ÿท๏ธ Generate Docker tags and labels id: docker-meta - uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5 + uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0 with: images: | docker.io/${{ secrets.DOCKERHUB_USERNAME }}/corvus @@ -638,7 +638,7 @@ jobs: - name: ๐Ÿณ Build and push Docker image (prebuilt binaries) continue-on-error: true - uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6 + uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 with: context: . file: clients/agent-runtime/Dockerfile.release-prebuilt @@ -658,10 +658,10 @@ jobs: packages: write steps: - name: โœˆ Checkout repository - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: โฌ‡ Download Cerebro Linux artifacts - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: pattern: cerebro-linux-* path: clients/cerebro/dist @@ -677,20 +677,20 @@ jobs: chmod +x cerebro-linux-x64 cerebro-linux-arm64 - name: ๐Ÿณ Set up QEMU - uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130 # v3 + uses: docker/setup-qemu-action@1f40c72289eff860ee54a304f1438e3cff362e0a # v4.3.0 - name: ๐Ÿณ Set up Docker Buildx - uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3 + uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0 - name: ๐Ÿ” Login to Docker Hub continue-on-error: true - uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3 + uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 with: username: ${{ secrets.DOCKERHUB_USERNAME }} password: ${{ secrets.DOCKERHUB_TOKEN }} - name: ๐Ÿ” Login to GitHub Container Registry - uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3 + uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 with: registry: ghcr.io username: ${{ github.actor }} @@ -698,7 +698,7 @@ jobs: - name: ๐Ÿท๏ธ Generate Cerebro Docker tags and labels id: docker-meta - uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5 + uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0 with: images: | docker.io/${{ secrets.DOCKERHUB_USERNAME }}/cerebro @@ -711,7 +711,7 @@ jobs: type=raw,value=beta,enable=${{ needs.publish.outputs.release_channel == 'beta' }} - name: ๐Ÿงช Build Cerebro Docker image for smoke test - uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6 + uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 with: context: . file: clients/cerebro/Dockerfile.release-prebuilt @@ -861,7 +861,7 @@ jobs: - name: ๐Ÿณ Build and push Cerebro Docker image continue-on-error: true - uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6 + uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 with: context: . file: clients/cerebro/Dockerfile.release-prebuilt @@ -881,10 +881,10 @@ jobs: packages: write steps: - name: โœˆ Checkout repository - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: โฌ‡ Download Rook Linux artifacts - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: pattern: rook-linux-* path: clients/rook/dist @@ -900,20 +900,20 @@ jobs: chmod +x rook-linux-x64 rook-linux-arm64 - name: ๐Ÿณ Set up QEMU - uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130 # v3 + uses: docker/setup-qemu-action@1f40c72289eff860ee54a304f1438e3cff362e0a # v4.3.0 - name: ๐Ÿณ Set up Docker Buildx - uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3 + uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0 - name: ๐Ÿ” Login to Docker Hub continue-on-error: true - uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3 + uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 with: username: ${{ secrets.DOCKERHUB_USERNAME }} password: ${{ secrets.DOCKERHUB_TOKEN }} - name: ๐Ÿ” Login to GitHub Container Registry - uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3 + uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 with: registry: ghcr.io username: ${{ github.actor }} @@ -921,7 +921,7 @@ jobs: - name: ๐Ÿท๏ธ Generate Rook Docker tags and labels id: docker-meta - uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5 + uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0 with: images: | docker.io/${{ secrets.DOCKERHUB_USERNAME }}/rook @@ -935,7 +935,7 @@ jobs: - name: ๐Ÿณ Build and push Rook Docker image continue-on-error: true - uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6 + uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 with: context: . file: clients/rook/Dockerfile.release-prebuilt @@ -978,16 +978,16 @@ jobs: source_binary: corvus-windows-x64.exe steps: - name: โœˆ Checkout repository - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: ๐Ÿ“ฆ Setup Node.js - uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: "24" registry-url: "https://registry.npmjs.org" - name: โฌ‡ Download artifact - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: ${{ matrix.artifact }} path: /tmp/artifact @@ -1080,10 +1080,10 @@ jobs: contents: read steps: - name: โœˆ Checkout repository - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: ๐Ÿ“ฆ Setup Node.js - uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: "24" registry-url: "https://registry.npmjs.org" @@ -1166,16 +1166,16 @@ jobs: source_binary: rook-windows-x64.exe steps: - name: โœˆ Checkout repository - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: ๐Ÿ“ฆ Setup Node.js - uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: "24" registry-url: "https://registry.npmjs.org" - name: โฌ‡ Download artifact - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: ${{ matrix.artifact }} path: /tmp/artifact @@ -1241,10 +1241,10 @@ jobs: contents: read steps: - name: โœˆ Checkout repository - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: ๐Ÿ“ฆ Setup Node.js - uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: "24" registry-url: "https://registry.npmjs.org" @@ -1294,7 +1294,7 @@ jobs: steps: - name: โฌ‡ Download corvus release artifacts - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: pattern: corvus-* path: dist/corvus @@ -1302,7 +1302,7 @@ jobs: if-no-files-found: error - name: โฌ‡ Download cerebro release artifacts - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: pattern: cerebro-* path: dist/cerebro @@ -1310,7 +1310,7 @@ jobs: if-no-files-found: error - name: โฌ‡ Download rook release artifacts - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: pattern: rook-* path: dist/rook diff --git a/.github/workflows/auto-fix-lockfile.yml b/.github/workflows/auto-fix-lockfile.yml index a5d5ebd5..2fb6adb6 100644 --- a/.github/workflows/auto-fix-lockfile.yml +++ b/.github/workflows/auto-fix-lockfile.yml @@ -21,17 +21,17 @@ jobs: steps: - name: โœˆ Checkout default branch if: github.event_name != 'issue_comment' - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 1 - name: ๐Ÿ“ฆ Setup pnpm - uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061 # v4 + uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v4 with: version: 10 - name: ๐Ÿ“ฆ Setup Node - uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: "24" cache: "pnpm" @@ -42,7 +42,7 @@ jobs: clients/web/apps/marketing/pnpm-lock.yaml - name: โ˜• Setup Java - uses: actions/setup-java@be666c2fcd27ec809703dec50e508c2fdc7f6654 # v5.2.0 + uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 with: java-version: "25" distribution: "corretto" @@ -51,7 +51,7 @@ jobs: run: rustup toolchain install 1.92 --profile minimal --component rustfmt --component clippy - name: ๐Ÿ˜ Setup Gradle - uses: gradle/actions/setup-gradle@0723195856401067f7a2779048b490ace7a47d7c # v5.0.2 + uses: gradle/actions/setup-gradle@9c971963bec38e04b3d30dcc455b5382be2fdbfb # v6.3.0 with: gradle-version: wrapper cache-read-only: false @@ -69,7 +69,7 @@ jobs: id: auto-pr-lockfile env: SKIP_GIT_HOOKS: "1" - uses: peter-evans/create-pull-request@98357b18bf14b5342f975ff684046ec3b2a07725 # v8.0.0 + uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1 with: token: ${{ secrets.GITHUB_TOKEN }} branch: "auto-pr/fix-lockfile" diff --git a/.github/workflows/cleanup-cache.yml b/.github/workflows/cleanup-cache.yml index bde84ea2..c6376eee 100644 --- a/.github/workflows/cleanup-cache.yml +++ b/.github/workflows/cleanup-cache.yml @@ -10,5 +10,5 @@ jobs: permissions: actions: write contents: read - uses: dallay/common-actions/.github/workflows/cleanup-cache.yml@6ecd716dcfb6a9e8a9c494d1eac210cc1d73d75f # v2.0.0 + uses: dallay/common-actions/.github/workflows/cleanup-cache.yml@69060250307677655136ca88c70a2f77cb4153b2 # v2.2.4 secrets: inherit diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml old mode 100755 new mode 100644 index 55f9cb64..875c00b9 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -35,26 +35,26 @@ jobs: steps: - name: โœˆ Checkout repository - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: ๐Ÿ“ฆ Setup pnpm - uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061 # v4 + uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v4 with: version: 10 - name: ๐Ÿ“ฆ Setup Node - uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: "24" - name: โ˜• Setup Java - uses: actions/setup-java@be666c2fcd27ec809703dec50e508c2fdc7f6654 # v5.2.0 + uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 with: java-version: "25" distribution: "corretto" - name: ๐Ÿ˜ Setup Gradle - uses: gradle/actions/setup-gradle@0723195856401067f7a2779048b490ace7a47d7c # v5.0.2 + uses: gradle/actions/setup-gradle@9c971963bec38e04b3d30dcc455b5382be2fdbfb # v6.3.0 with: gradle-version: wrapper @@ -65,7 +65,7 @@ jobs: run: ./gradlew --version - name: โš™๏ธ Initialize CodeQL - uses: github/codeql-action/init@v3 + uses: github/codeql-action/init@v4 with: languages: ${{ matrix.language }} build-mode: ${{ matrix.build-mode }} @@ -83,8 +83,8 @@ jobs: - name: ๐Ÿ” Run CodeQL Analysis (java-kotlin) if: > steps.gradle_build_java_kotlin.outcome == 'success' - uses: github/codeql-action/analyze@v3 + uses: github/codeql-action/analyze@v4 - name: ๐Ÿ” Run CodeQL Analysis if: matrix.language != 'java-kotlin' - uses: github/codeql-action/analyze@v3 + uses: github/codeql-action/analyze@v4 diff --git a/.github/workflows/core-check.yml b/.github/workflows/core-check.yml index 3b66554f..0b501ac5 100644 --- a/.github/workflows/core-check.yml +++ b/.github/workflows/core-check.yml @@ -42,18 +42,18 @@ jobs: steps: - name: โœˆ Checkout default branch - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 1 - name: โ˜• Setup Java - uses: actions/setup-java@be666c2fcd27ec809703dec50e508c2fdc7f6654 # v5.2.0 + uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 with: java-version: "25" distribution: "corretto" - name: ๐Ÿ˜ Setup Gradle - uses: gradle/actions/setup-gradle@0723195856401067f7a2779048b490ace7a47d7c # v5.0.2 + uses: gradle/actions/setup-gradle@9c971963bec38e04b3d30dcc455b5382be2fdbfb # v6.3.0 with: gradle-version: wrapper cache-read-only: false @@ -87,7 +87,7 @@ jobs: output.write(f"profile={profile}\n") - name: ๐Ÿฆ€ Setup Rust toolchain - uses: dtolnay/rust-toolchain@f7ccc83f9ed1e5b9c81d8a67d7ad1a747e22a561 + uses: dtolnay/rust-toolchain@d1031067263f94b142dd6c0ce24c5eb9d02d52a0 with: toolchain: ${{ steps.rust-channel.outputs.channel }} components: ${{ steps.rust-channel.outputs.components }} diff --git a/.github/workflows/dashboard-accessibility.yml b/.github/workflows/dashboard-accessibility.yml index 434f8f6b..c85d7d8f 100644 --- a/.github/workflows/dashboard-accessibility.yml +++ b/.github/workflows/dashboard-accessibility.yml @@ -38,17 +38,17 @@ jobs: steps: - name: โœˆ Checkout repository - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 1 - name: ๐Ÿ“ฆ Setup pnpm - uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061 # v4 + uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v4 with: version: 10 - name: ๐Ÿ“ฆ Setup Node - uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: "24" cache: "pnpm" diff --git a/.github/workflows/dependabot-auto-merge.yml b/.github/workflows/dependabot-auto-merge.yml index 1c7b5216..e45326a5 100644 --- a/.github/workflows/dependabot-auto-merge.yml +++ b/.github/workflows/dependabot-auto-merge.yml @@ -4,7 +4,7 @@ on: types: [opened, synchronize, reopened] jobs: auto-merge: - uses: dallay/common-actions/.github/workflows/dependabot-auto-merge.yml@v2.0.0 + uses: dallay/common-actions/.github/workflows/dependabot-auto-merge.yml@v2.2.4 with: target: squash approve: true diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index 8d338c0d..3c9944bd 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -19,9 +19,9 @@ jobs: contents: read steps: - name: โœˆ Checkout repository - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 - name: ๐Ÿ” Dependency Review - uses: actions/dependency-review-action@05fe4576374b728f0c523d6a13d64c25081e0803 # v4.8.3 + uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5.0.0 diff --git a/.github/workflows/deploy-docs.yml b/.github/workflows/deploy-docs.yml index b7ae520a..ad79db63 100644 --- a/.github/workflows/deploy-docs.yml +++ b/.github/workflows/deploy-docs.yml @@ -26,17 +26,17 @@ jobs: working-directory: clients/web/apps/docs steps: - name: Checkout repository - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: ref: ${{ inputs.docs_ref }} - name: Setup pnpm - uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061 # v4 + uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v4 with: version: 10 - name: Setup Node.js - uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: 24 cache: "pnpm" @@ -49,7 +49,7 @@ jobs: run: pnpm run build - name: Upload artifact - uses: actions/upload-pages-artifact@7b1f4a764d45c48632c6b24a0339c27f5614fb0b # v4 + uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0 with: path: clients/web/apps/docs/dist @@ -65,4 +65,4 @@ jobs: steps: - name: Deploy to GitHub Pages id: deployment - uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e # v4 + uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 # v5.0.1 diff --git a/.github/workflows/detekt.yml b/.github/workflows/detekt.yml index 624e9f2d..7458131f 100644 --- a/.github/workflows/detekt.yml +++ b/.github/workflows/detekt.yml @@ -72,7 +72,7 @@ jobs: # Steps represent a sequence of tasks that will be executed as part of the job steps: # Checks-out your repository under $GITHUB_WORKSPACE, so your job can access it - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 1 @@ -149,7 +149,7 @@ jobs: mv "$tmp_sarif" "${{ github.workspace }}/detekt.sarif.json" # Uploads results to GitHub repository using the upload-sarif action - - uses: github/codeql-action/upload-sarif@cdefb33c0f6224e58673d9004f47f7cb3e328b89 # v4.31.10 + - uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 with: # Path to SARIF file relative to the root of the repository sarif_file: ${{ github.workspace }}/detekt.sarif.json diff --git a/.github/workflows/docs-quality.yml b/.github/workflows/docs-quality.yml index 33ed0150..b1f64d10 100644 --- a/.github/workflows/docs-quality.yml +++ b/.github/workflows/docs-quality.yml @@ -41,17 +41,17 @@ jobs: working-directory: clients/web/apps/docs steps: - name: Checkout repository - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 - name: Setup pnpm - uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061 # v4 + uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v4 with: version: 10 - name: Setup Node.js - uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: 24 cache: pnpm @@ -77,7 +77,7 @@ jobs: - name: Upload docs preview artifact if: success() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: docs-preview-${{ github.run_id }} path: clients/web/apps/docs/dist diff --git a/.github/workflows/fix-renovate.yml b/.github/workflows/fix-renovate.yml index 45b86091..7aac6df1 100644 --- a/.github/workflows/fix-renovate.yml +++ b/.github/workflows/fix-renovate.yml @@ -32,7 +32,7 @@ jobs: steps: - name: ๐Ÿ“ก Get PR Data if: github.event_name == 'issue_comment' && github.event.issue.pull_request != null - uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0 + uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 id: get-pr-data with: # language=javascript @@ -74,7 +74,7 @@ jobs: echo "The repository is ${{ steps.get-pr-data.outputs.head_repo }}" - name: โœˆ Checkout PR commit - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 1 repository: ${{ steps.get-pr-data.outputs.head_repo }} @@ -92,12 +92,12 @@ jobs: fi - name: ๐Ÿ“ฆ Setup pnpm - uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061 # v4 + uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v4 with: version: 10 - name: ๐Ÿ“ฆ Setup Node - uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: "24" cache: "pnpm" @@ -108,7 +108,7 @@ jobs: clients/web/apps/marketing/pnpm-lock.yaml - name: โ˜• Setup Java - uses: actions/setup-java@be666c2fcd27ec809703dec50e508c2fdc7f6654 # v5.2.0 + uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 with: java-version: "25" distribution: "corretto" @@ -117,7 +117,7 @@ jobs: run: rustup toolchain install 1.92 --profile minimal --component rustfmt --component clippy - name: ๐Ÿ˜ Setup Gradle - uses: gradle/actions/setup-gradle@0723195856401067f7a2779048b490ace7a47d7c # v5.0.2 + uses: gradle/actions/setup-gradle@9c971963bec38e04b3d30dcc455b5382be2fdbfb # v6.3.0 with: gradle-version: wrapper cache-read-only: false @@ -129,7 +129,7 @@ jobs: run: ./gradlew --version - name: ๐Ÿ” Re-validate PR head SHA before write actions - uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0 + uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 env: EXPECTED_SHA: ${{ steps.get-pr-data.outputs.head_sha }} EXPECTED_REPO: ${{ steps.get-pr-data.outputs.head_repo }} @@ -185,7 +185,7 @@ jobs: git diff --cached --quiet || git commit -m "${COMMIT_MSG}" - name: ๐Ÿ” Re-validate PR head SHA before push - uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0 + uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 env: EXPECTED_SHA: ${{ steps.get-pr-data.outputs.head_sha }} EXPECTED_REPO: ${{ steps.get-pr-data.outputs.head_repo }} diff --git a/.github/workflows/git-issue-auto-close.yml b/.github/workflows/git-issue-auto-close.yml old mode 100755 new mode 100644 index dfb14f44..06b6787b --- a/.github/workflows/git-issue-auto-close.yml +++ b/.github/workflows/git-issue-auto-close.yml @@ -14,7 +14,7 @@ jobs: steps: - name: ๐Ÿ˜ž Check labels and close inactive issues - uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0 + uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: script: | const inactiveDays = 7 diff --git a/.github/workflows/git-issue-labeled.yml b/.github/workflows/git-issue-labeled.yml old mode 100755 new mode 100644 index 277f3ae7..f9495484 --- a/.github/workflows/git-issue-labeled.yml +++ b/.github/workflows/git-issue-labeled.yml @@ -17,7 +17,7 @@ jobs: steps: - name: ๐Ÿค” status|waiting-reproduction if: github.event.label.name == 'status|waiting-reproduction' - uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0 + uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: script: | const issueNumber = context.issue.number @@ -36,7 +36,7 @@ jobs: - name: ๐Ÿฅด close|stackoverflow if: github.event.label.name == 'close|stackoverflow' - uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0 + uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: script: | const issueNumber = context.issue.number diff --git a/.github/workflows/git-sync-labels.yml b/.github/workflows/git-sync-labels.yml index 594a00a0..69da021f 100644 --- a/.github/workflows/git-sync-labels.yml +++ b/.github/workflows/git-sync-labels.yml @@ -21,7 +21,7 @@ jobs: timeout-minutes: 10 steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 1 sparse-checkout: ".github/config/labels.yml" diff --git a/.github/workflows/greetings.yml b/.github/workflows/greetings.yml index 60cae5b3..fd926f05 100644 --- a/.github/workflows/greetings.yml +++ b/.github/workflows/greetings.yml @@ -8,5 +8,5 @@ jobs: permissions: issues: write pull-requests: write - uses: dallay/common-actions/.github/workflows/greetings.yml@6ecd716dcfb6a9e8a9c494d1eac210cc1d73d75f # v2.0.0 + uses: dallay/common-actions/.github/workflows/greetings.yml@69060250307677655136ca88c70a2f77cb4153b2 # v2.2.4 secrets: inherit diff --git a/.github/workflows/lychee-links.yml b/.github/workflows/lychee-links.yml index a37a2a0b..0cffdd03 100644 --- a/.github/workflows/lychee-links.yml +++ b/.github/workflows/lychee-links.yml @@ -21,18 +21,18 @@ jobs: steps: - name: Generate GitHub App Token id: app-token - uses: actions/create-github-app-token@29824e69f54612133e76f7eaac726eef6c875baf # v2 + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v2 with: app-id: ${{ secrets.APP_ID }} private-key: ${{ secrets.APP_PRIVATE_KEY }} - name: โœˆ Checkout repository - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 1 - name: ๐Ÿ”— Restore lychee cache - uses: actions/cache@0c907a75c2c80ebcb7f088228285e798b750cf8f # v4.2.1 + uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 with: path: .lycheecache key: cache-lychee-${{ github.sha }} @@ -40,7 +40,7 @@ jobs: - name: ๐Ÿ”— Check links id: lychee - uses: lycheeverse/lychee-action@8646ba30535128ac92d33dfc9133794bfdd9b411 # v2.8.0 + uses: lycheeverse/lychee-action@e7477775783ea5526144ba13e8db5eec57747ce8 # v2.9.0 with: args: --config ./lychee.toml --no-progress . output: ./lychee/out.md @@ -110,7 +110,7 @@ jobs: fi - name: ๐Ÿ’พ Save lychee cache - uses: actions/cache/save@0c907a75c2c80ebcb7f088228285e798b750cf8f # v4.2.1 + uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 if: always() with: path: .lycheecache diff --git a/.github/workflows/osv-scanner.yml b/.github/workflows/osv-scanner.yml index f10cf08b..ba5f9b62 100644 --- a/.github/workflows/osv-scanner.yml +++ b/.github/workflows/osv-scanner.yml @@ -29,7 +29,7 @@ permissions: jobs: scan-scheduled: if: ${{ github.event_name == 'push' || github.event_name == 'schedule' }} - uses: "google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml@eb5b619bb565d10623076caba5263750fde3c790" # v2.3.5 + uses: "google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml@8e5cf47b818121e8b405931c82126c2630b0b20d" # v2.3.5 with: # Example of specifying custom arguments scan-args: |- @@ -38,7 +38,7 @@ jobs: ./ scan-pr: if: ${{ github.event_name == 'pull_request' || github.event_name == 'merge_group' }} - uses: "google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml@eb5b619bb565d10623076caba5263750fde3c790" # v2.3.5 + uses: "google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml@8e5cf47b818121e8b405931c82126c2630b0b20d" # v2.3.5 with: # Example of specifying custom arguments scan-args: |- diff --git a/.github/workflows/pr-size-labeler.yml b/.github/workflows/pr-size-labeler.yml index a652119d..cc590ee1 100644 --- a/.github/workflows/pr-size-labeler.yml +++ b/.github/workflows/pr-size-labeler.yml @@ -11,4 +11,4 @@ jobs: contents: read issues: write pull-requests: write - uses: dallay/common-actions/.github/workflows/pr-size-labeler.yml@6ecd716dcfb6a9e8a9c494d1eac210cc1d73d75f # v2.0.0 + uses: dallay/common-actions/.github/workflows/pr-size-labeler.yml@69060250307677655136ca88c70a2f77cb4153b2 # v2.2.4 diff --git a/.github/workflows/publish-release.yml b/.github/workflows/publish-release.yml index 7aecd35e..4da9f416 100644 --- a/.github/workflows/publish-release.yml +++ b/.github/workflows/publish-release.yml @@ -24,7 +24,7 @@ jobs: supported_release: ${{ steps.scope.outputs.supported_release }} steps: - name: โœˆ Checkout repository - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: ๐Ÿงญ Resolve release scope from tag id: scope diff --git a/.github/workflows/pull-request-check-build-logic.yml b/.github/workflows/pull-request-check-build-logic.yml index b4511b57..6452fced 100644 --- a/.github/workflows/pull-request-check-build-logic.yml +++ b/.github/workflows/pull-request-check-build-logic.yml @@ -38,23 +38,23 @@ jobs: steps: - name: โœˆ Checkout default branch if: github.event_name != 'issue_comment' - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 1 - name: ๐Ÿ“ฆ Setup Node - uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: "24" - name: โ˜• Setup Java - uses: actions/setup-java@be666c2fcd27ec809703dec50e508c2fdc7f6654 # v5.2.0 + uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 with: java-version: "25" distribution: "corretto" - name: ๐Ÿ˜ Setup Gradle - uses: gradle/actions/setup-gradle@0723195856401067f7a2779048b490ace7a47d7c # v5.0.2 + uses: gradle/actions/setup-gradle@9c971963bec38e04b3d30dcc455b5382be2fdbfb # v6.3.0 with: gradle-version: wrapper cache-read-only: false diff --git a/.github/workflows/pull-request-check.yml b/.github/workflows/pull-request-check.yml index 47d502f3..60234cc4 100644 --- a/.github/workflows/pull-request-check.yml +++ b/.github/workflows/pull-request-check.yml @@ -35,7 +35,7 @@ jobs: steps: - name: โœˆ Checkout default branch - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 1 @@ -56,12 +56,12 @@ jobs: # git merge --no-ff target-branch - name: ๐Ÿ“ฆ Setup pnpm - uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061 # v4 + uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v4 with: version: 10 - name: ๐Ÿ“ฆ Setup Node - uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: "24" cache: "pnpm" @@ -72,13 +72,13 @@ jobs: clients/web/apps/marketing/pnpm-lock.yaml - name: โ˜• Setup Java - uses: actions/setup-java@be666c2fcd27ec809703dec50e508c2fdc7f6654 # v5.2.0 + uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 with: java-version: "25" distribution: "corretto" - name: ๐Ÿ˜ Setup Gradle - uses: gradle/actions/setup-gradle@0723195856401067f7a2779048b490ace7a47d7c # v5.0.2 + uses: gradle/actions/setup-gradle@9c971963bec38e04b3d30dcc455b5382be2fdbfb # v6.3.0 with: gradle-version: wrapper cache-read-only: false @@ -111,7 +111,7 @@ jobs: output.write(f"channel={channel}\n") - name: ๐Ÿฆ€ Setup Rust toolchain - uses: dtolnay/rust-toolchain@f7ccc83f9ed1e5b9c81d8a67d7ad1a747e22a561 + uses: dtolnay/rust-toolchain@d1031067263f94b142dd6c0ce24c5eb9d02d52a0 with: toolchain: ${{ steps.rust-channel.outputs.channel }} components: rustfmt, clippy @@ -173,7 +173,7 @@ jobs: - name: ๐Ÿ“ค Upload Kotlin/Rust coverage to Codecov if: github.event_name != 'pull_request' && github.event_name != 'merge_group' && github.actor != 'dependabot[bot]' - uses: codecov/codecov-action@1af58845a975a7985b0beb0cbe6fbbb71a41dbad # v5.5.3 + uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0 with: fail_ci_if_error: true verbose: true @@ -184,7 +184,7 @@ jobs: - name: ๐Ÿ“ค Upload Web coverage to Codecov if: github.event_name != 'pull_request' && github.event_name != 'merge_group' && github.actor != 'dependabot[bot]' - uses: codecov/codecov-action@1af58845a975a7985b0beb0cbe6fbbb71a41dbad # v5.5.3 + uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0 with: fail_ci_if_error: true verbose: true diff --git a/.github/workflows/release-please-beta.yml b/.github/workflows/release-please-beta.yml index b22b7494..ce075e88 100644 --- a/.github/workflows/release-please-beta.yml +++ b/.github/workflows/release-please-beta.yml @@ -28,13 +28,13 @@ jobs: steps: - name: ๐Ÿ” Generate release GitHub App token id: app-token - uses: actions/create-github-app-token@f8d387b68d61c58ab83c6c016672934102569859 # v3 + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3 with: app-id: ${{ secrets.APP_ID }} private-key: ${{ secrets.APP_PRIVATE_KEY }} - name: ๐Ÿ“ฅ Checkout repository - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 token: ${{ steps.app-token.outputs.token }} @@ -80,7 +80,7 @@ jobs: - name: ๐Ÿค– Run release-please id: release-please - uses: googleapis/release-please-action@16a9c90856f42705d54a6fda1823352bdc62cf38 # v4.4.0 + uses: googleapis/release-please-action@45996ed1f6d02564a971a2fa1b5860e934307cf7 # v5.0.0 with: token: ${{ steps.app-token.outputs.token }} config-file: release-please-beta-config.json diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index df9533c2..b341e0bb 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -27,13 +27,13 @@ jobs: steps: - name: ๐Ÿ” Generate release GitHub App token id: app-token - uses: actions/create-github-app-token@f8d387b68d61c58ab83c6c016672934102569859 # v3 + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3 with: app-id: ${{ secrets.APP_ID }} private-key: ${{ secrets.APP_PRIVATE_KEY }} - name: ๐Ÿ“ฅ Checkout repository - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 token: ${{ steps.app-token.outputs.token }} @@ -79,7 +79,7 @@ jobs: - name: ๐Ÿค– Run release-please id: release-please - uses: googleapis/release-please-action@16a9c90856f42705d54a6fda1823352bdc62cf38 # v4.4.0 + uses: googleapis/release-please-action@45996ed1f6d02564a971a2fa1b5860e934307cf7 # v5.0.0 with: token: ${{ steps.app-token.outputs.token }} config-file: release-please-config.json diff --git a/.github/workflows/security-dependencies.yml b/.github/workflows/security-dependencies.yml index 6533634d..8c15e2af 100644 --- a/.github/workflows/security-dependencies.yml +++ b/.github/workflows/security-dependencies.yml @@ -23,17 +23,17 @@ jobs: contents: read steps: - name: โœˆ Checkout repository - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 1 - name: ๐Ÿฆ€ Setup Rust toolchain - uses: dtolnay/rust-toolchain@efa25f7f19611383d5b0ccf2d1c8914531636bf9 # master 2026-03-04 + uses: dtolnay/rust-toolchain@d1031067263f94b142dd6c0ce24c5eb9d02d52a0 # master 2026-03-04 with: toolchain: stable - name: ๐Ÿ“ฅ Install cargo-deny - uses: taiki-e/install-action@2dc1234c293fde032a8e34c74501c7d6403e92ae # v2.68.14 + uses: taiki-e/install-action@c3ec0de9ae7f1019cea21aa96aa0a895b9552063 # v2.87.9 with: tool: cargo-deny @@ -50,17 +50,17 @@ jobs: contents: write steps: - name: โœˆ Checkout repository - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 1 - name: โ˜• Setup Java - uses: actions/setup-java@be666c2fcd27ec809703dec50e508c2fdc7f6654 # v5.2.0 + uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 with: java-version: "25" distribution: "corretto" - name: ๐Ÿ˜ Submit Dependency Graph - uses: gradle/actions/dependency-submission@0723195856401067f7a2779048b490ace7a47d7c # v5.0.2 + uses: gradle/actions/dependency-submission@9c971963bec38e04b3d30dcc455b5382be2fdbfb # v6.3.0 with: gradle-version: wrapper diff --git a/.github/workflows/semantic-pull-request.yml b/.github/workflows/semantic-pull-request.yml index 8171578f..6d99116a 100644 --- a/.github/workflows/semantic-pull-request.yml +++ b/.github/workflows/semantic-pull-request.yml @@ -4,4 +4,4 @@ on: types: [opened, edited, synchronize] jobs: main: - uses: dallay/common-actions/.github/workflows/semantic-pull-request.yml@v2.0.0 \ No newline at end of file + uses: dallay/common-actions/.github/workflows/semantic-pull-request.yml@v2.2.4 \ No newline at end of file diff --git a/.github/workflows/sonarqube-analysis.yml b/.github/workflows/sonarqube-analysis.yml index 0d920ac5..34964a6d 100644 --- a/.github/workflows/sonarqube-analysis.yml +++ b/.github/workflows/sonarqube-analysis.yml @@ -37,7 +37,7 @@ jobs: steps: - name: โœˆ Checkout repository - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 @@ -50,20 +50,20 @@ jobs: - name: โ˜• Setup Java if: env.SONAR_TOKEN != '' - uses: actions/setup-java@be666c2fcd27ec809703dec50e508c2fdc7f6654 # v5.2.0 + uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 with: java-version: "25" distribution: "corretto" - name: ๐Ÿ“ฆ Setup pnpm if: env.SONAR_TOKEN != '' - uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061 # v4 + uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v4 with: version: 10 - name: ๐Ÿ“ฆ Setup Node if: env.SONAR_TOKEN != '' - uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: "24" cache: "pnpm" @@ -76,7 +76,7 @@ jobs: - name: ๐Ÿ˜ Setup Gradle if: env.SONAR_TOKEN != '' - uses: gradle/actions/setup-gradle@0723195856401067f7a2779048b490ace7a47d7c # v5.0.2 + uses: gradle/actions/setup-gradle@9c971963bec38e04b3d30dcc455b5382be2fdbfb # v6.3.0 with: gradle-version: wrapper @@ -97,13 +97,13 @@ jobs: - name: ๐Ÿฆ€ Setup Rust if: env.SONAR_TOKEN != '' - uses: dtolnay/rust-toolchain@efa25f7f19611383d5b0ccf2d1c8914531636bf9 # HEAD as of 2026-03-04 + uses: dtolnay/rust-toolchain@d1031067263f94b142dd6c0ce24c5eb9d02d52a0 # HEAD as of 2026-03-04 with: toolchain: 1.92 - name: ๐Ÿ“ฆ Install cargo-llvm-cov if: env.SONAR_TOKEN != '' - uses: taiki-e/install-action@2834d6555cea49e0759c35c2a877ea0228e73e06 # cargo-llvm-cov + uses: taiki-e/install-action@2dc1234c293fde032a8e34c74501c7d6403e92ae # cargo-llvm-cov - name: ๐Ÿ“ Create coverage directory if: env.SONAR_TOKEN != '' @@ -122,7 +122,7 @@ jobs: - name: ๐Ÿ” SonarQube scan if: env.SONAR_TOKEN != '' - uses: SonarSource/sonarqube-scan-action@fd88b7d7ccbaefd23d8f36f73b59db7a3d246602 # v6 + uses: SonarSource/sonarqube-scan-action@22918119ff8e1ca75a623e15c8296b6ea4fbe28f # v8.2.1 env: SONAR_TOKEN: ${{ env.SONAR_TOKEN }} with: @@ -152,7 +152,7 @@ jobs: github.event_name == 'pull_request' || (github.event_name == 'push' && github.ref == 'refs/heads/main') ) - uses: SonarSource/sonarqube-quality-gate-action@d304d050d930b02a896b0f85935344f023928496 # v1 + uses: SonarSource/sonarqube-quality-gate-action@7a5fffe8e523c40e0c740b6bc2712ab503e52efa # v1 timeout-minutes: 5 env: SONAR_TOKEN: ${{ env.SONAR_TOKEN }} diff --git a/.github/workflows/stale.yml b/.github/workflows/stale.yml index 834dfe16..c2908174 100644 --- a/.github/workflows/stale.yml +++ b/.github/workflows/stale.yml @@ -10,5 +10,5 @@ jobs: permissions: issues: write pull-requests: write - uses: dallay/common-actions/.github/workflows/stale.yml@6ecd716dcfb6a9e8a9c494d1eac210cc1d73d75f # v2.0.0 + uses: dallay/common-actions/.github/workflows/stale.yml@69060250307677655136ca88c70a2f77cb4153b2 # v2.2.4 secrets: inherit diff --git a/.github/workflows/sync-cargo-lockfiles.yml b/.github/workflows/sync-cargo-lockfiles.yml index 534294c5..7ce13b47 100644 --- a/.github/workflows/sync-cargo-lockfiles.yml +++ b/.github/workflows/sync-cargo-lockfiles.yml @@ -22,13 +22,13 @@ jobs: steps: - name: ๐Ÿ” Generate GitHub App token id: app-token - uses: actions/create-github-app-token@f8d387b68d61c58ab83c6c016672934102569859 # v3 + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3 with: app-id: ${{ secrets.APP_ID }} private-key: ${{ secrets.APP_PRIVATE_KEY }} - name: โœˆ Checkout PR branch - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: ref: ${{ github.head_ref }} token: ${{ steps.app-token.outputs.token }} @@ -56,7 +56,7 @@ jobs: output.write(f"channel={channel}\n") - name: ๐Ÿฆ€ Setup Rust toolchain - uses: dtolnay/rust-toolchain@f7ccc83f9ed1e5b9c81d8a67d7ad1a747e22a561 + uses: dtolnay/rust-toolchain@d1031067263f94b142dd6c0ce24c5eb9d02d52a0 with: toolchain: ${{ steps.rust-channel.outputs.channel }}