From c6aff27ef88cfe39ff8dc4e870d458a4a306e410 Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Thu, 8 Oct 2026 18:46:47 +0000 Subject: [PATCH] deps: Update GitHub Actions --- .github/workflows/android-lint.yml | 2 +- .github/workflows/ci.yml | 6 +++--- .github/workflows/codeql.yml | 4 ++-- .github/workflows/gradle-wrapper-validation.yml | 2 +- .github/workflows/play-check.yml | 2 +- .github/workflows/play-publish.yml | 2 +- .github/workflows/release.yml | 2 +- .github/workflows/scorecard.yml | 4 ++-- 8 files changed, 12 insertions(+), 12 deletions(-) diff --git a/.github/workflows/android-lint.yml b/.github/workflows/android-lint.yml index b24b22ff..352122fc 100644 --- a/.github/workflows/android-lint.yml +++ b/.github/workflows/android-lint.yml @@ -48,7 +48,7 @@ jobs: - name: Upload lint report if: always() - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 + uses: actions/upload-artifact@cf430e030ddbb5b0abf93d22962f4752f3646cd9 # v7 with: name: android-lint-report path: | diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index e34d39ea..c979de05 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -50,7 +50,7 @@ jobs: run: ./gradlew :app:assembleDebug --no-daemon - name: Upload debug APK - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 + uses: actions/upload-artifact@cf430e030ddbb5b0abf93d22962f4752f3646cd9 # v7 with: name: app-debug-apk path: app/build/outputs/apk/debug/*.apk @@ -104,7 +104,7 @@ jobs: # Upload to Codecov for the trend graph + README badge (tokenless OIDC # upload works for public repositories). - name: Upload coverage to Codecov - uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7 + uses: codecov/codecov-action@303a32d7a59b442fa8d48b6a1cc6825c09c847a5 # v7 with: files: app/build/reports/kover/reportDebug.xml flags: unittests @@ -113,7 +113,7 @@ jobs: # Keep the raw report as a downloadable artifact. - name: Upload coverage report artifact - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 + uses: actions/upload-artifact@cf430e030ddbb5b0abf93d22962f4752f3646cd9 # v7 with: name: coverage-report path: app/build/reports/kover/reportDebug.xml diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index c1f8ad47..a2cbe97d 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -39,7 +39,7 @@ jobs: cache: gradle - name: Initialize CodeQL - uses: github/codeql-action/init@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4 + uses: github/codeql-action/init@24c54180a607b1449ed407dd24f251e4e9147c8d # v4 with: languages: java-kotlin queries: security-and-quality @@ -51,6 +51,6 @@ jobs: run: ./gradlew :app:assembleFdroidDebug --no-daemon - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4 + uses: github/codeql-action/analyze@24c54180a607b1449ed407dd24f251e4e9147c8d # v4 with: category: "/language:java-kotlin" diff --git a/.github/workflows/gradle-wrapper-validation.yml b/.github/workflows/gradle-wrapper-validation.yml index bc769791..88ab6901 100644 --- a/.github/workflows/gradle-wrapper-validation.yml +++ b/.github/workflows/gradle-wrapper-validation.yml @@ -33,5 +33,5 @@ jobs: persist-credentials: false - name: Validate wrapper checksum - uses: gradle/actions/wrapper-validation@9c971963bec38e04b3d30dcc455b5382be2fdbfb # v6 + uses: gradle/actions/wrapper-validation@3f5f9adaf7d9fecd50b5935e54106014257a94e6 # v6 diff --git a/.github/workflows/play-check.yml b/.github/workflows/play-check.yml index 4b6134cf..253968ce 100644 --- a/.github/workflows/play-check.yml +++ b/.github/workflows/play-check.yml @@ -28,7 +28,7 @@ jobs: - name: Set up Ruby (fastlane) uses: ruby/setup-ruby@v1 with: - ruby-version: "4.0.6" + ruby-version: "4.0.7" bundler-cache: true - name: Validate Play service account env: diff --git a/.github/workflows/play-publish.yml b/.github/workflows/play-publish.yml index af3cc47c..64c18e61 100644 --- a/.github/workflows/play-publish.yml +++ b/.github/workflows/play-publish.yml @@ -149,7 +149,7 @@ jobs: - name: Set up Ruby (fastlane) uses: ruby/setup-ruby@v1 with: - ruby-version: "4.0.6" + ruby-version: "4.0.7" bundler-cache: true - name: Publish selected components diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 5d67bcfe..63f5100d 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -188,7 +188,7 @@ jobs: # ── Create GitHub Release ───────────────────────────────────────────────── - name: Create GitHub Release - uses: softprops/action-gh-release@3d0d9888cb7fd7b750713d6e236d1fcb99157228 # v3 + uses: softprops/action-gh-release@efb35369e0ad2afab669f228072c1b0d510eae64 # v3 with: tag_name: ${{ steps.version.outputs.tag }} name: "VeloSpot ${{ steps.version.outputs.tag }}" diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index c2915c05..7216fc12 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -45,7 +45,7 @@ jobs: # Upload the raw SARIF as a workflow artifact (retained 5 days) so the # detailed findings can be inspected even outside the Security tab. - name: Upload artifact - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 + uses: actions/upload-artifact@cf430e030ddbb5b0abf93d22962f4752f3646cd9 # v7 with: name: SARIF file path: results.sarif @@ -53,7 +53,7 @@ jobs: # Surface the findings in the repository's Security → Code scanning tab. - name: Upload to code-scanning - uses: github/codeql-action/upload-sarif@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4 + uses: github/codeql-action/upload-sarif@24c54180a607b1449ed407dd24f251e4e9147c8d # v4 with: sarif_file: results.sarif