diff --git a/.github/workflow-templates/ci.yml b/.github/workflow-templates/ci.yml index 6218705..d047442 100644 --- a/.github/workflow-templates/ci.yml +++ b/.github/workflow-templates/ci.yml @@ -33,4 +33,4 @@ concurrency: jobs: ci: - uses: cplieger/ci/.github/workflows/ci.yaml@06e673c8341ac85645a7cafb6911eb01d5816f3d # v2 + uses: cplieger/ci/.github/workflows/ci.yaml@d072f88e5845f2c49a47317fe61378786bbe4154 # v2 diff --git a/.github/workflow-templates/codeql.yml b/.github/workflow-templates/codeql.yml index 77b54ec..1ad2ad9 100644 --- a/.github/workflow-templates/codeql.yml +++ b/.github/workflow-templates/codeql.yml @@ -16,4 +16,4 @@ jobs: security-events: write contents: read actions: read - uses: cplieger/ci/.github/workflows/codeql.yaml@06e673c8341ac85645a7cafb6911eb01d5816f3d # v2 + uses: cplieger/ci/.github/workflows/codeql.yaml@d072f88e5845f2c49a47317fe61378786bbe4154 # v2 diff --git a/.github/workflow-templates/coverage.yml b/.github/workflow-templates/coverage.yml index 67ebb53..7b06889 100644 --- a/.github/workflow-templates/coverage.yml +++ b/.github/workflow-templates/coverage.yml @@ -27,4 +27,4 @@ jobs: # NOTE: pin this @SHA to the ci release tag that first contains # coverage.yaml when cutting that tag (see ci.md "Updating and propagating"). # Renovate then tracks the `# v2` comment and bumps the digest thereafter. - uses: cplieger/ci/.github/workflows/coverage.yaml@06e673c8341ac85645a7cafb6911eb01d5816f3d # v2 + uses: cplieger/ci/.github/workflows/coverage.yaml@d072f88e5845f2c49a47317fe61378786bbe4154 # v2 diff --git a/.github/workflow-templates/release.yml b/.github/workflow-templates/release.yml index d14bfa8..c2d91c9 100644 --- a/.github/workflow-templates/release.yml +++ b/.github/workflow-templates/release.yml @@ -63,7 +63,7 @@ jobs: id-token: write attestations: write security-events: write - uses: cplieger/ci/.github/workflows/release.yaml@06e673c8341ac85645a7cafb6911eb01d5816f3d # v2 + uses: cplieger/ci/.github/workflows/release.yaml@d072f88e5845f2c49a47317fe61378786bbe4154 # v2 # Forward only the two Docker Hub publish credentials the reusable pipeline # actually declares and consumes, rather than `secrets: inherit` (which # exposes every repo secret to the reusable-workflow trust boundary). Both diff --git a/.github/workflow-templates/security.yml b/.github/workflow-templates/security.yml index f116f84..fe7d0ec 100644 --- a/.github/workflow-templates/security.yml +++ b/.github/workflow-templates/security.yml @@ -22,4 +22,4 @@ jobs: permissions: contents: read security-events: write - uses: cplieger/ci/.github/workflows/security-scan.yaml@06e673c8341ac85645a7cafb6911eb01d5816f3d # v2 + uses: cplieger/ci/.github/workflows/security-scan.yaml@d072f88e5845f2c49a47317fe61378786bbe4154 # v2 diff --git a/.github/workflows/coverage.yaml b/.github/workflows/coverage.yaml index 286f311..d283e97 100644 --- a/.github/workflows/coverage.yaml +++ b/.github/workflows/coverage.yaml @@ -102,7 +102,7 @@ jobs: # move. - name: Publish coverage badge if: ${{ steps.d.outputs.kind != 'none' }} - uses: cplieger/ci/actions/publish-badge@06e673c8341ac85645a7cafb6911eb01d5816f3d # v2 + uses: cplieger/ci/actions/publish-badge@d072f88e5845f2c49a47317fe61378786bbe4154 # v2 with: repo: ${{ github.repository }} token: ${{ github.token }} diff --git a/.github/workflows/docker-release.yaml b/.github/workflows/docker-release.yaml index a50c095..77abf80 100644 --- a/.github/workflows/docker-release.yaml +++ b/.github/workflows/docker-release.yaml @@ -757,7 +757,7 @@ jobs: - name: Publish image-size badge if: ${{ steps.sizebadge.outputs.json != '' }} continue-on-error: true - uses: cplieger/ci/actions/publish-badge@06e673c8341ac85645a7cafb6911eb01d5816f3d # v2 + uses: cplieger/ci/actions/publish-badge@d072f88e5845f2c49a47317fe61378786bbe4154 # v2 with: repo: ${{ github.repository }} token: ${{ github.token }} diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index fb4289c..2fd3745 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -117,7 +117,7 @@ jobs: # resolves against the CONSUMER's checked-out workspace, not this # repo, so it 404s when release.yaml is called from another repo. This # action's content is stable, so pin-lag is a non-issue here. - uses: cplieger/ci/actions/git-cliff-version@06e673c8341ac85645a7cafb6911eb01d5816f3d # v2 + uses: cplieger/ci/actions/git-cliff-version@d072f88e5845f2c49a47317fe61378786bbe4154 # v2 - name: Detect type + subpackages id: type