Skip to content

Commit d650b89

Browse files
authored
Merge pull request #5 from IntimateMerger/chore/pinact-update-actions-and-dependabot
chore(ci): pin/update GitHub Actions (pinact) and add Dependabot
2 parents 3369ec5 + 20e4539 commit d650b89

3 files changed

Lines changed: 25 additions & 13 deletions

File tree

.github/dependabot.yml

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
version: 2
2+
updates:
3+
- package-ecosystem: "github-actions"
4+
directory: "/"
5+
schedule:
6+
interval: "weekly"
7+
groups:
8+
github-actions:
9+
patterns:
10+
- "*"
11+
cooldown:
12+
default-days: 7

.github/workflows/build-and-push.yaml

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -36,20 +36,20 @@ jobs:
3636

3737
steps:
3838
- name: Checkout code
39-
uses: actions/checkout@v6
39+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
4040

4141
- name: Set up Docker Buildx
42-
uses: docker/setup-buildx-action@v3
42+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
4343

4444
- name: Log in to Docker Hub
45-
uses: docker/login-action@v3
45+
uses: docker/login-action@b45d80f862d83dbcd57f89517bcf500b2ab88fb2 # v4.0.0
4646
with:
4747
username: ${{ vars.DOCKERHUB_USERNAME }}
4848
password: ${{ secrets.DOCKERHUB_TOKEN_PUBLIC }}
4949

5050
- name: Build and push by digest
5151
id: build
52-
uses: docker/build-push-action@v6
52+
uses: docker/build-push-action@d08e5c354a6adb9ed34480a06d141179aa583294 # v7.0.0
5353
with:
5454
context: .
5555
platforms: ${{ matrix.platform }}
@@ -66,7 +66,7 @@ jobs:
6666
touch "/tmp/digests/${digest#sha256:}"
6767
6868
- name: Upload digest
69-
uses: actions/upload-artifact@v6
69+
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
7070
with:
7171
name: digests-${{ matrix.arch }}
7272
path: /tmp/digests/*
@@ -82,17 +82,17 @@ jobs:
8282

8383
steps:
8484
- name: Download digests
85-
uses: actions/download-artifact@v7
85+
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
8686
with:
8787
path: /tmp/digests
8888
pattern: digests-*
8989
merge-multiple: true
9090

9191
- name: Set up Docker Buildx
92-
uses: docker/setup-buildx-action@v3
92+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
9393

9494
- name: Log in to Docker Hub
95-
uses: docker/login-action@v3
95+
uses: docker/login-action@b45d80f862d83dbcd57f89517bcf500b2ab88fb2 # v4.0.0
9696
with:
9797
username: ${{ vars.DOCKERHUB_USERNAME }}
9898
password: ${{ secrets.DOCKERHUB_TOKEN_PUBLIC }}
@@ -124,7 +124,7 @@ jobs:
124124
125125
- name: Docker meta
126126
id: meta
127-
uses: docker/metadata-action@v5
127+
uses: docker/metadata-action@030e881283bb7a6894de51c315a6bfe6a94e05cf # v6.0.0
128128
with:
129129
images: ${{ env.DOCKER_IMAGE }}
130130
tags: |
@@ -161,7 +161,7 @@ jobs:
161161
162162
- name: Docker Scout CVE scan
163163
if: github.ref == 'refs/heads/master' || github.ref == 'refs/heads/main'
164-
uses: docker/scout-action@v1
164+
uses: docker/scout-action@8910519cee8ac046f3ee99686b0dc6654d5ba1a7 # v1.20.3
165165
continue-on-error: true
166166
with:
167167
command: cves

.github/workflows/security-scan.yaml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -20,18 +20,18 @@ jobs:
2020

2121
steps:
2222
- name: Checkout code
23-
uses: actions/checkout@v6
23+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
2424

2525
- name: Run Trivy vulnerability scanner
26-
uses: aquasecurity/trivy-action@master
26+
uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # v0.35.0
2727
with:
2828
scan-type: 'config'
2929
scan-ref: '.'
3030
format: 'sarif'
3131
output: 'trivy-results.sarif'
3232

3333
- name: Upload Trivy results to GitHub Security
34-
uses: github/codeql-action/upload-sarif@v4
34+
uses: github/codeql-action/upload-sarif@38697555549f1db7851b81482ff19f1fa5c4fedc # v4.34.1
3535
if: always()
3636
with:
3737
sarif_file: 'trivy-results.sarif'

0 commit comments

Comments
 (0)