diff --git a/.github/workflows/abi-drift.yml b/.github/workflows/abi-drift.yml
index cb1f06e5..6da5276f 100644
--- a/.github/workflows/abi-drift.yml
+++ b/.github/workflows/abi-drift.yml
@@ -46,7 +46,7 @@ jobs:
outputs:
run: ${{ steps.detect.outputs.run }}
steps:
- - uses: actions/checkout@v6.0.2
+ - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0
- id: detect
@@ -71,7 +71,7 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- - uses: actions/checkout@v6.0.2
+ - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
# Need at least two commits so `git diff origin/...HEAD`
# can compute the changed-cartridge set on pull_request events.
@@ -79,7 +79,9 @@ jobs:
fetch-depth: 0
- name: Install Rust toolchain (stable)
- uses: dtolnay/rust-toolchain@v1
+ uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # v1
+ with:
+ toolchain: v1
with:
toolchain: stable
@@ -91,7 +93,7 @@ jobs:
# GADT-skip fix (iseriser#20, merged 2026-05-20) never reached CI.
# Bumping ISERISER_REV invalidates the cache and forces a rebuild.
- name: Cache cargo bin (iseriser install)
- uses: actions/cache@v4.2.2
+ uses: actions/cache@d4323d4df104b026a6aa633fdb11d772146be0bf # v4.2.2
env:
ISERISER_REV: 741a3b63e7619b6e9cfe7f91b04d7ccfb130b1ca
with:
diff --git a/.github/workflows/backend-assurance.yml b/.github/workflows/backend-assurance.yml
index 165fde61..ff931033 100644
--- a/.github/workflows/backend-assurance.yml
+++ b/.github/workflows/backend-assurance.yml
@@ -47,7 +47,7 @@ jobs:
outputs:
run: ${{ steps.detect.outputs.run }}
steps:
- - uses: actions/checkout@v6.0.2
+ - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0
- id: detect
@@ -79,16 +79,16 @@ jobs:
run:
working-directory: elixir
steps:
- - uses: actions/checkout@v6.0.2
+ - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Set up BEAM (Elixir + OTP)
- uses: erlef/setup-beam@v1.24.0
+ uses: erlef/setup-beam@fc68ffb90438ef2936bbb3251622353b3dcb2f93 # v1.24.0
with:
elixir-version: '1.18.4'
otp-version: '27.0'
- name: Cache deps + _build
- uses: actions/cache@v4.2.2
+ uses: actions/cache@d4323d4df104b026a6aa633fdb11d772146be0bf # v4.2.2
with:
path: |
elixir/deps
diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml
index f5b88b7d..5e2e069c 100644
--- a/.github/workflows/build.yml
+++ b/.github/workflows/build.yml
@@ -22,10 +22,10 @@ jobs:
name: SonarQube
runs-on: ubuntu-latest
steps:
- - uses: actions/checkout@v4.3.1
+ - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
with:
fetch-depth: 0 # Shallow clones should be disabled for a better relevancy of analysis
- name: SonarQube Scan
- uses: SonarSource/sonarqube-scan-action@v8.1.0
+ uses: SonarSource/sonarqube-scan-action@7006c4492b2e0ee0f816d36501671557c97f5995 # v8.1.0
env:
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml
index d7a89b22..39792b2b 100644
--- a/.github/workflows/codeql.yml
+++ b/.github/workflows/codeql.yml
@@ -43,15 +43,15 @@ jobs:
steps:
- name: Checkout
- uses: actions/checkout@v6.0.2
+ uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Initialize CodeQL
- uses: github/codeql-action/init@v4.34.0
+ uses: github/codeql-action/init@c6f931105cb2c34c8f901cc885ba1e2e259cf745 # v4.34.0
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}
- name: Perform CodeQL Analysis
- uses: github/codeql-action/analyze@v4.34.0
+ uses: github/codeql-action/analyze@c6f931105cb2c34c8f901cc885ba1e2e259cf745 # v4.34.0
with:
category: "/language:${{ matrix.language }}"
diff --git a/.github/workflows/container-publish.yml b/.github/workflows/container-publish.yml
index 5117331c..0a49344d 100644
--- a/.github/workflows/container-publish.yml
+++ b/.github/workflows/container-publish.yml
@@ -28,7 +28,7 @@ jobs:
id-token: write # mint the OIDC token the attestation is signed with
attestations: write # write the build-provenance attestation (the "claim")
steps:
- - uses: actions/checkout@v6.0.2
+ - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Extract version metadata
id: meta
@@ -93,7 +93,7 @@ jobs:
# gh attest verify oci://ghcr.io/${{ github.repository }}: \
# --repo ${{ github.repository }}
- name: Attest container provenance
- uses: actions/attest-build-provenance@v2.4.0
+ uses: actions/attest-build-provenance@e8998f949152b193b063cb0ec769d69d929409be # v2.4.0
with:
subject-name: ghcr.io/${{ github.repository }}
subject-digest: ${{ steps.push.outputs.digest }}
diff --git a/.github/workflows/dogfood-gate.yml b/.github/workflows/dogfood-gate.yml
index b926c72a..629d3f45 100644
--- a/.github/workflows/dogfood-gate.yml
+++ b/.github/workflows/dogfood-gate.yml
@@ -37,7 +37,7 @@ jobs:
steps:
- name: Checkout repository
- uses: actions/checkout@v6.0.2
+ uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Check for A2ML files
id: detect
@@ -78,7 +78,7 @@ jobs:
steps:
- name: Checkout repository
- uses: actions/checkout@v6.0.2
+ uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Check for K9 files
id: detect
@@ -124,7 +124,7 @@ jobs:
steps:
- name: Checkout repository
- uses: actions/checkout@v6.0.2
+ uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Scan for invisible characters
id: lint
@@ -220,7 +220,7 @@ jobs:
steps:
- name: Checkout repository
- uses: actions/checkout@v6.0.2
+ uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Check for Groove manifest
id: groove
@@ -279,7 +279,7 @@ jobs:
steps:
- name: Checkout repository
- uses: actions/checkout@v6.0.2
+ uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Check and validate eclexiaiser manifest
id: eclex
@@ -327,7 +327,7 @@ jobs:
steps:
- name: Checkout repository
- uses: actions/checkout@v6.0.2
+ uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Generate dogfooding scorecard
run: |
diff --git a/.github/workflows/e2e.yml b/.github/workflows/e2e.yml
index b1407a5a..fc8583d7 100644
--- a/.github/workflows/e2e.yml
+++ b/.github/workflows/e2e.yml
@@ -34,7 +34,7 @@ jobs:
outputs:
run: ${{ steps.detect.outputs.run }}
steps:
- - uses: actions/checkout@v6.0.2
+ - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0
- id: detect
@@ -66,15 +66,15 @@ jobs:
steps:
- name: Checkout
- uses: actions/checkout@v6.0.2
+ uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Install Zig
- uses: mlugg/setup-zig@v2.2.1
+ uses: mlugg/setup-zig@d1434d08867e3ee9daa34448df10607b98908d29 # v2.2.1
with:
version: 0.16.0
- name: Install Deno
- uses: denoland/setup-deno@v2.0.4
+ uses: denoland/setup-deno@667a34cdef165d8d2b2e98dde39547c9daac7282 # v2.0.4
with:
deno-version: v2.x
@@ -82,7 +82,7 @@ jobs:
# tests/e2e_full.sh requires `mix` on PATH to start the Elixir
# backend (elixir/ — `mix run --no-halt`). Pinned to match the
# estate convention (see hypatia-scan.yml across the org).
- uses: erlef/setup-beam@v1.24.0
+ uses: erlef/setup-beam@fc68ffb90438ef2936bbb3251622353b3dcb2f93 # v1.24.0
with:
elixir-version: '1.18'
otp-version: '27'
@@ -115,7 +115,7 @@ jobs:
- name: Upload test logs
if: always()
- uses: actions/upload-artifact@v4.6.2
+ uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: e2e-full-logs
path: /tmp/boj-e2e-test.*
@@ -131,10 +131,10 @@ jobs:
steps:
- name: Checkout
- uses: actions/checkout@v6.0.2
+ uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Install Zig
- uses: mlugg/setup-zig@v2.2.1
+ uses: mlugg/setup-zig@d1434d08867e3ee9daa34448df10607b98908d29 # v2.2.1
with:
version: 0.16.0
@@ -154,7 +154,7 @@ jobs:
steps:
- name: Checkout
- uses: actions/checkout@v6.0.2
+ uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Run aspect tests
run: bash tests/aspect_tests.sh
@@ -169,10 +169,10 @@ jobs:
steps:
- name: Checkout
- uses: actions/checkout@v6.0.2
+ uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Install Zig
- uses: mlugg/setup-zig@v2.2.1
+ uses: mlugg/setup-zig@d1434d08867e3ee9daa34448df10607b98908d29 # v2.2.1
with:
version: 0.16.0
@@ -184,7 +184,7 @@ jobs:
- name: Upload benchmark results
if: always()
- uses: actions/upload-artifact@v4.6.2
+ uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: benchmark-results
path: ffi/zig/zig-out/bench*
@@ -223,24 +223,24 @@ jobs:
steps:
- name: Checkout
- uses: actions/checkout@v6.0.2
+ uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Setup Node
# Node is needed on every leg: it is the subject on the node
# leg and the boot-smoke orchestrator on all three.
- uses: actions/setup-node@v4.4.0
+ uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version: '22'
- name: Install Deno
if: matrix.runtime == 'deno'
- uses: denoland/setup-deno@v2.0.4
+ uses: denoland/setup-deno@667a34cdef165d8d2b2e98dde39547c9daac7282 # v2.0.4
with:
deno-version: v2.x
- name: Install Bun
if: matrix.runtime == 'bun'
- uses: oven-sh/setup-bun@v2.2.0
+ uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
with:
bun-version: '1.x'
@@ -269,10 +269,10 @@ jobs:
steps:
- name: Checkout
- uses: actions/checkout@v6.0.2
+ uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Setup Node
- uses: actions/setup-node@v4.4.0
+ uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version: '22'
@@ -281,7 +281,7 @@ jobs:
- name: Upload bridge bench artifact
if: always()
- uses: actions/upload-artifact@v4.6.2
+ uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: bench-bridge-results
path: bench-bridge.txt
@@ -292,7 +292,7 @@ jobs:
# Advisory — a comment failure must never gate the bench job.
# Same reasoning as the hypatia-scan PR-comment step.
continue-on-error: true
- uses: actions/github-script@v8.0.0
+ uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0
with:
script: |
const fs = require('fs');
diff --git a/.github/workflows/fuzz.yml b/.github/workflows/fuzz.yml
index f1972f0d..abc61fc3 100644
--- a/.github/workflows/fuzz.yml
+++ b/.github/workflows/fuzz.yml
@@ -27,10 +27,10 @@ jobs:
permissions:
contents: read
steps:
- - uses: actions/checkout@v6.0.2
+ - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Install Zig
- uses: mlugg/setup-zig@v2.2.1
+ uses: mlugg/setup-zig@d1434d08867e3ee9daa34448df10607b98908d29 # v2.2.1
with:
version: 0.16.0
@@ -55,7 +55,7 @@ jobs:
permissions:
contents: read
steps:
- - uses: actions/checkout@v6.0.2
+ - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Fuzz JSON-RPC message parsing
run: |
diff --git a/.github/workflows/hcg-surface-drift.yml b/.github/workflows/hcg-surface-drift.yml
index f83cb9df..40eef2d4 100644
--- a/.github/workflows/hcg-surface-drift.yml
+++ b/.github/workflows/hcg-surface-drift.yml
@@ -52,7 +52,7 @@ jobs:
outputs:
run: ${{ steps.detect.outputs.run }}
steps:
- - uses: actions/checkout@v6.0.2
+ - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0
- id: detect
@@ -87,7 +87,7 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- - uses: actions/checkout@v6.0.2
+ - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Confirm script + inputs are present
run: |
set -euo pipefail
diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml
index 234621fc..2bbba20a 100644
--- a/.github/workflows/hypatia-scan.yml
+++ b/.github/workflows/hypatia-scan.yml
@@ -50,12 +50,12 @@ jobs:
steps:
- name: Checkout repository
- uses: actions/checkout@v6.0.2
+ uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0 # Full history for better pattern analysis
- name: Setup Elixir for Hypatia scanner
- uses: erlef/setup-beam@v1.24.0
+ uses: erlef/setup-beam@fc68ffb90438ef2936bbb3251622353b3dcb2f93 # v1.24.0
with:
elixir-version: '1.18'
otp-version: '27'
@@ -109,7 +109,7 @@ jobs:
echo "- Medium: $MEDIUM" >> $GITHUB_STEP_SUMMARY
- name: Upload findings artifact
- uses: actions/upload-artifact@v4.6.2
+ uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: hypatia-findings
path: hypatia-findings.json
@@ -245,7 +245,7 @@ jobs:
always() &&
(github.event_name != 'pull_request' ||
github.event.pull_request.head.repo.fork != true)
- uses: github/codeql-action/upload-sarif@v4.32.6
+ uses: github/codeql-action/upload-sarif@0d579ffd059c29b07949a3cce3983f0780820c98 # v4.32.6
with:
sarif_file: hypatia.sarif
# Distinct category so Hypatia results coexist with CodeQL's
@@ -385,7 +385,7 @@ jobs:
# the pull-requests: write permission above: a token/API hiccup or
# a fork PR (read-only token) skips the comment, not the check.
continue-on-error: true
- uses: actions/github-script@v8.0.0
+ uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0
with:
script: |
const fs = require('fs');
diff --git a/.github/workflows/instant-sync.yml b/.github/workflows/instant-sync.yml
index 6eca04d6..658c1a7d 100644
--- a/.github/workflows/instant-sync.yml
+++ b/.github/workflows/instant-sync.yml
@@ -28,7 +28,7 @@ jobs:
timeout-minutes: 5
steps:
- name: Trigger Propagation
- uses: peter-evans/repository-dispatch@v3.0.0
+ uses: peter-evans/repository-dispatch@ff45666b9427631e3450c54a1bcbee4d9ff4d7c0 # v3.0.0
with:
token: ${{ secrets.FARM_DISPATCH_TOKEN }}
repository: hyperpolymath/.git-private-farm
diff --git a/.github/workflows/lsp-dap-bsp.yml b/.github/workflows/lsp-dap-bsp.yml
index 338820fc..ae9fba89 100644
--- a/.github/workflows/lsp-dap-bsp.yml
+++ b/.github/workflows/lsp-dap-bsp.yml
@@ -32,7 +32,7 @@ jobs:
outputs:
run: ${{ steps.detect.outputs.run }}
steps:
- - uses: actions/checkout@v6.0.2
+ - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0
- id: detect
@@ -58,7 +58,7 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- - uses: actions/checkout@v6.0.2
+ - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Validate ABI modules exist
run: |
echo "=== Checking LSP/DAP/BSP ABI modules ==="
@@ -94,13 +94,13 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- - uses: actions/checkout@v6.0.2
+ - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
# Use the pinned action + .tool-versions' canonical Zig, matching
# e2e.yml. (A previous revision curled ziglang.org/builds/... — the
# nightly dir, not release downloads — and got an error page that
# `tar` rejected.)
- name: Install Zig
- uses: mlugg/setup-zig@v2.2.1
+ uses: mlugg/setup-zig@d1434d08867e3ee9daa34448df10607b98908d29 # v2.2.1
with:
version: 0.16.0
- name: Build LSP/DAP/BSP cartridge FFI
@@ -141,7 +141,7 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- - uses: actions/checkout@v6.0.2
+ - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
# jq (pre-installed on ubuntu-latest) — the repo's no-Python policy
# (dogfood-gate) bans the previous json.tool/json.load approach.
# Same checks: valid JSON + required fields + panel count.
@@ -175,7 +175,7 @@ jobs:
needs: [changes, abi-check, ffi-build, panel-validation]
if: needs.changes.outputs.run == 'true'
steps:
- - uses: actions/checkout@v6.0.2
+ - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Verify triadic structure
run: |
echo "=== LSP/DAP/BSP Triadic Structure Audit ==="
diff --git a/.github/workflows/pages-deploy.yml b/.github/workflows/pages-deploy.yml
index 85dbef0f..403dcacc 100644
--- a/.github/workflows/pages-deploy.yml
+++ b/.github/workflows/pages-deploy.yml
@@ -21,7 +21,7 @@ jobs:
deploy:
runs-on: ubuntu-latest
steps:
- - uses: actions/checkout@v4.4.0
+ - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
- name: Deploy site/ to Cloudflare Workers (static assets)
run: npx wrangler@latest deploy
env:
diff --git a/.github/workflows/pages.yml b/.github/workflows/pages.yml
index 276ad2d1..70bfa21e 100755
--- a/.github/workflows/pages.yml
+++ b/.github/workflows/pages.yml
@@ -26,9 +26,9 @@ jobs:
image: ghcr.io/stefan-hoeck/idris2-pack@sha256:f0758996a931fb35d9ecb1de273c4d59dabe2a09b433afc7e357f65a08b7e1ff
steps:
- name: Checkout Site
- uses: actions/checkout@v4.4.0
+ uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
- name: Checkout Ddraig SSG
- uses: actions/checkout@v4.4.0
+ uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
with:
repository: hyperpolymath/ddraig-ssg
path: .ddraig-ssg
@@ -45,7 +45,7 @@ jobs:
fi
./.ddraig-ssg/build/exec/ddraig build src _site https://hyperpolymath.github.io/${GITHUB_REPOSITORY#*/}
- name: Upload artifact
- uses: actions/upload-pages-artifact@v3.0.1
+ uses: actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa # v3.0.1
with:
path: '_site'
deploy:
@@ -58,4 +58,4 @@ jobs:
steps:
- name: Deploy to GitHub Pages
id: deployment
- uses: actions/deploy-pages@v4.0.5
+ uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e # v4.0.5
diff --git a/.github/workflows/proofs.yml b/.github/workflows/proofs.yml
index 5376c3c3..f122e8f4 100644
--- a/.github/workflows/proofs.yml
+++ b/.github/workflows/proofs.yml
@@ -52,7 +52,7 @@ jobs:
outputs:
run: ${{ steps.detect.outputs.run }}
steps:
- - uses: actions/checkout@v6.0.2
+ - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0
- id: detect
@@ -82,7 +82,7 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- - uses: actions/checkout@v6.0.2
+ - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Enforce trusted base
run: bash scripts/check-trusted-base.sh
@@ -94,7 +94,7 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 45
steps:
- - uses: actions/checkout@v6.0.2
+ - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Read pinned Idris2 version
id: ver
@@ -104,7 +104,7 @@ jobs:
run: sudo apt-get update && sudo apt-get install -y chezscheme libgmp-dev build-essential
- name: Cache asdf + Idris2 toolchain
- uses: actions/cache@v4.2.2
+ uses: actions/cache@d4323d4df104b026a6aa633fdb11d772146be0bf # v4.2.2
with:
path: ~/.asdf
key: idris2-asdf-${{ runner.os }}-${{ steps.ver.outputs.idris2 }}
diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml
index c551b5bf..d4263cc3 100644
--- a/.github/workflows/publish.yml
+++ b/.github/workflows/publish.yml
@@ -25,10 +25,10 @@ jobs:
contents: read
id-token: write
steps:
- - uses: actions/checkout@v6.0.2
+ - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Setup Node.js
- uses: actions/setup-node@v4.4.0
+ uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version: '22'
registry-url: 'https://registry.npmjs.org'
@@ -55,10 +55,10 @@ jobs:
contents: read
id-token: write
steps:
- - uses: actions/checkout@v6.0.2
+ - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Setup Deno
- uses: denoland/setup-deno@v2.0.4
+ uses: denoland/setup-deno@667a34cdef165d8d2b2e98dde39547c9daac7282 # v2.0.4
with:
deno-version: v2.x
diff --git a/.github/workflows/push-email-notify.yml b/.github/workflows/push-email-notify.yml
index 9e133d7c..8c43f1c0 100644
--- a/.github/workflows/push-email-notify.yml
+++ b/.github/workflows/push-email-notify.yml
@@ -40,7 +40,7 @@ jobs:
timeout-minutes: 5
steps:
- name: Send push notification email
- uses: hyperpolymath/smtp-notify-action@v0.2.0 # NOSONAR — pin authority is actions.lock (sha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7)
+ uses: hyperpolymath/smtp-notify-action@ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7 # NOSONAR — pin authority is actions.lock (sha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7)
with:
server_address: ${{ secrets.SMTP_HOST }}
server_port: ${{ secrets.SMTP_PORT }}
diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml
index 429abeb7..9d224994 100644
--- a/.github/workflows/release.yml
+++ b/.github/workflows/release.yml
@@ -27,10 +27,10 @@ jobs:
outputs:
hashes: ${{ steps.hash.outputs.hashes }}
steps:
- - uses: actions/checkout@v6.0.2
+ - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Install Zig
- uses: mlugg/setup-zig@v2.2.1
+ uses: mlugg/setup-zig@d1434d08867e3ee9daa34448df10607b98908d29 # v2.2.1
with:
version: 0.16.0
@@ -76,7 +76,7 @@ jobs:
echo "hashes=${HASHES}" >> "$GITHUB_OUTPUT"
- name: Upload build artifacts
- uses: actions/upload-artifact@v4.6.2
+ uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: release-artifacts
path: boj-server-*-linux-x86_64.tar.gz
@@ -92,7 +92,7 @@ jobs:
changelog: ${{ steps.cliff.outputs.content }}
version: ${{ steps.version.outputs.version }}
steps:
- - uses: actions/checkout@v6.0.2
+ - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0
@@ -122,7 +122,7 @@ jobs:
git cliff --output CHANGELOG.md
- name: Upload updated CHANGELOG.md
- uses: actions/upload-artifact@v4.6.2
+ uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: changelog
path: CHANGELOG.md
@@ -136,16 +136,16 @@ jobs:
permissions:
contents: write
steps:
- - uses: actions/checkout@v6.0.2
+ - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Download build artifacts
- uses: actions/download-artifact@v4.2.1
+ uses: actions/download-artifact@95815c38cf2ff2164869cbab79da8d1f422bc89e # v4.2.1
with:
name: release-artifacts
path: artifacts/
- name: Create GitHub Release
- uses: softprops/action-gh-release@v2.6.2
+ uses: softprops/action-gh-release@3bb12739c298aeb8a4eeaf626c5b8d85266b0e65 # v2.6.2
with:
body: ${{ needs.changelog.outputs.changelog }}
draft: false
diff --git a/.github/workflows/truthfulness.yml b/.github/workflows/truthfulness.yml
index c1d93eb9..1306b1c4 100644
--- a/.github/workflows/truthfulness.yml
+++ b/.github/workflows/truthfulness.yml
@@ -36,7 +36,7 @@ jobs:
outputs:
run: ${{ steps.detect.outputs.run }}
steps:
- - uses: actions/checkout@v6.0.2
+ - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0
- id: detect
@@ -67,10 +67,10 @@ jobs:
steps:
- name: Checkout
- uses: actions/checkout@v6.0.2
+ uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Install Zig
- uses: mlugg/setup-zig@v2.2.1
+ uses: mlugg/setup-zig@d1434d08867e3ee9daa34448df10607b98908d29 # v2.2.1
with:
version: 0.16.0
diff --git a/.github/workflows/zig-test.yml b/.github/workflows/zig-test.yml
index 9ca840f2..69ebf4fd 100644
--- a/.github/workflows/zig-test.yml
+++ b/.github/workflows/zig-test.yml
@@ -33,7 +33,7 @@ jobs:
outputs:
run: ${{ steps.detect.outputs.run }}
steps:
- - uses: actions/checkout@v6.0.2
+ - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0
- id: detect
@@ -64,10 +64,10 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- - uses: actions/checkout@v6.0.2
+ - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Install Zig
- uses: mlugg/setup-zig@v2.2.1
+ uses: mlugg/setup-zig@d1434d08867e3ee9daa34448df10607b98908d29 # v2.2.1
with:
version: 0.16.0