diff --git a/.github/workflows/_parse_version.yml b/.github/workflows/_parse_version.yml index 1a36ceed2ac..f77494e5d31 100644 --- a/.github/workflows/_parse_version.yml +++ b/.github/workflows/_parse_version.yml @@ -107,7 +107,7 @@ jobs: timeout-minutes: 2 - name: Upload patch - uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # pin v4.4.3 + uses: actions/upload-artifact@6f51ac03b9356f520e9adb1b1b7802705f340c2b # pin v4.5.0 with: name: version.patch path: | diff --git a/.github/workflows/ci-python.yml b/.github/workflows/ci-python.yml index 0655370336f..2052dceda78 100644 --- a/.github/workflows/ci-python.yml +++ b/.github/workflows/ci-python.yml @@ -141,7 +141,7 @@ jobs: timeout-minutes: 5 - name: Retrieve Rust cache - uses: Swatinem/rust-cache@82a92a6e8fbeee089604da2575dc567ae9ddeaab # pin v2.7.5 + uses: Swatinem/rust-cache@f0deed1e0edfc6a9be95417288c0e1099b1eeec3 # pin v2.7.7 if: steps.cache-libparsec.outputs.cache-hit != 'true' with: # Cache is limited to 10Go (and cache is ~700mo per platform !). On top of that. diff --git a/.github/workflows/ci-rust.yml b/.github/workflows/ci-rust.yml index 71d477adc75..f0778975cc5 100644 --- a/.github/workflows/ci-rust.yml +++ b/.github/workflows/ci-rust.yml @@ -82,7 +82,7 @@ jobs: timeout-minutes: 10 - name: Retrieve Rust cache - uses: Swatinem/rust-cache@82a92a6e8fbeee089604da2575dc567ae9ddeaab # pin v2.7.5 + uses: Swatinem/rust-cache@f0deed1e0edfc6a9be95417288c0e1099b1eeec3 # pin v2.7.7 with: # Cache is limited to 10Go (and cache is ~700mo per platform !). On top of that. # cache is only shared between master and the PRs (and not across PRs). @@ -102,7 +102,7 @@ jobs: timeout-minutes: 5 # Install cargo nextest command - - uses: taiki-e/install-action@acf70b3a1ed953bccebc8c5d80cfdb16ec8ccc36 # pin v2.46.4 + - uses: taiki-e/install-action@acd25891978b4cdaebd139d3efef606d26513b14 # pin v2.47.0 with: tool: nextest@0.9.54, wasm-pack@0.12.1, cargo-deny@0.15.0 @@ -229,7 +229,7 @@ jobs: timeout-minutes: 10 - name: Retrieve Rust cache - uses: Swatinem/rust-cache@82a92a6e8fbeee089604da2575dc567ae9ddeaab # pin v2.7.5 + uses: Swatinem/rust-cache@f0deed1e0edfc6a9be95417288c0e1099b1eeec3 # pin v2.7.7 with: # Cache is limited to 10Go (and cache is ~700mo per platform !). On top of that. # cache is only shared between master and the PRs (and not across PRs). @@ -263,7 +263,7 @@ jobs: timeout-minutes: 5 # Install cargo nextest command - - uses: taiki-e/install-action@acf70b3a1ed953bccebc8c5d80cfdb16ec8ccc36 # pin v2.46.4 + - uses: taiki-e/install-action@acd25891978b4cdaebd139d3efef606d26513b14 # pin v2.47.0 with: tool: nextest@0.9.54 diff --git a/.github/workflows/ci-web.yml b/.github/workflows/ci-web.yml index b24fa1fa4af..dde78a8f497 100644 --- a/.github/workflows/ci-web.yml +++ b/.github/workflows/ci-web.yml @@ -111,7 +111,7 @@ jobs: timeout-minutes: 5 - name: Retrieve Rust cache - uses: Swatinem/rust-cache@82a92a6e8fbeee089604da2575dc567ae9ddeaab # pin v2.7.5 + uses: Swatinem/rust-cache@f0deed1e0edfc6a9be95417288c0e1099b1eeec3 # pin v2.7.7 if: steps.cache-libparsec.outputs.cache-hit != 'true' with: # Cache is limited to 10Go (and cache is ~700mo per platform !). On top of that. @@ -123,7 +123,7 @@ jobs: timeout-minutes: 5 # Install wasm-pack command - - uses: taiki-e/install-action@acf70b3a1ed953bccebc8c5d80cfdb16ec8ccc36 # pin v2.46.4 + - uses: taiki-e/install-action@acd25891978b4cdaebd139d3efef606d26513b14 # pin v2.47.0 with: tool: wasm-pack@${{ env.wasm-pack-version }} @@ -165,7 +165,7 @@ jobs: - name: Archive test results if: failure() - uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # pin v4.4.3 + uses: actions/upload-artifact@6f51ac03b9356f520e9adb1b1b7802705f340c2b # pin v4.5.0 with: name: playwright-artifacts path: client/test-results/ diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 97bdd08e02e..b7089c42152 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -191,7 +191,7 @@ jobs: diff --unified .pre-commit-config.yaml $TEMP_FILE || true echo "path=$TEMP_FILE" >> $GITHUB_OUTPUT - - uses: taiki-e/install-action@acf70b3a1ed953bccebc8c5d80cfdb16ec8ccc36 # pin v2.46.4 + - uses: taiki-e/install-action@acd25891978b4cdaebd139d3efef606d26513b14 # pin v2.47.0 with: tool: taplo-cli@0.9.3 diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 7187114a2bc..22508ae145a 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -58,7 +58,7 @@ jobs: # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL if: steps.should-run-python-analysis.outputs.run == 'true' - uses: github/codeql-action/init@aa578102511db1f4524ed59b8cc2bae4f6e88195 # pin v3.27.6 + uses: github/codeql-action/init@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 # pin v3.28.0 with: languages: python setup-python-dependencies: false @@ -87,7 +87,7 @@ jobs: - name: Perform CodeQL Analysis if: steps.should-run-python-analysis.outputs.run == 'true' - uses: github/codeql-action/analyze@aa578102511db1f4524ed59b8cc2bae4f6e88195 # pin v3.27.6 + uses: github/codeql-action/analyze@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 # pin v3.28.0 with: category: /language:python @@ -142,7 +142,7 @@ jobs: # # Initializes the CodeQL tools for scanning. # - name: Initialize CodeQL # if: steps.should-run-java-analysis.outputs.run == 'true' - # uses: github/codeql-action/init@aa578102511db1f4524ed59b8cc2bae4f6e88195 # pin v3.27.6 + # uses: github/codeql-action/init@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 # pin v3.28.0 # with: # languages: java # # If you wish to specify custom queries, you can do so here or in a config file. @@ -154,7 +154,7 @@ jobs: # - name: Autobuild android # if: steps.should-run-java-analysis.outputs.run == 'true' - # uses: github/codeql-action/autobuild@aa578102511db1f4524ed59b8cc2bae4f6e88195 # pin v3.27.6 + # uses: github/codeql-action/autobuild@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 # pin v3.28.0 # with: # working-directory: client/android # env: @@ -162,7 +162,7 @@ jobs: # - name: Perform CodeQL Analysis # if: steps.should-run-java-analysis.outputs.run == 'true' - # uses: github/codeql-action/analyze@aa578102511db1f4524ed59b8cc2bae4f6e88195 # pin v3.27.6 + # uses: github/codeql-action/analyze@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 # pin v3.28.0 # with: # category: /language:java @@ -191,7 +191,7 @@ jobs: # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL if: steps.should-run-js-analysis.outputs.run == 'true' - uses: github/codeql-action/init@aa578102511db1f4524ed59b8cc2bae4f6e88195 # pin v3.27.6 + uses: github/codeql-action/init@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 # pin v3.28.0 with: languages: typescript @@ -202,12 +202,12 @@ jobs: - name: Autobuild for typescript if: steps.should-run-js-analysis.outputs.run == 'true' - uses: github/codeql-action/autobuild@aa578102511db1f4524ed59b8cc2bae4f6e88195 # pin v3.27.6 + uses: github/codeql-action/autobuild@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 # pin v3.28.0 with: working-directory: client - name: Perform CodeQL Analysis if: steps.should-run-js-analysis.outputs.run == 'true' - uses: github/codeql-action/analyze@aa578102511db1f4524ed59b8cc2bae4f6e88195 # pin v3.27.6 + uses: github/codeql-action/analyze@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 # pin v3.28.0 with: category: /language:typescript diff --git a/.github/workflows/cspell.yml b/.github/workflows/cspell.yml index b0259776f9b..659a4af3f4f 100644 --- a/.github/workflows/cspell.yml +++ b/.github/workflows/cspell.yml @@ -74,7 +74,7 @@ jobs: - name: Check spelling in the repository id: cspell - uses: streetsidesoftware/cspell-action@9759be9ad475fe8145f8d2a1bf29a1c4d1c6f18d # pin v6.9.0 + uses: streetsidesoftware/cspell-action@ef95dc49d631fc2a9e9ea089ae2b2127b7c4588e # pin v6.10.0 with: config: .cspell/cspell.config.yml # Only check for changed files on a PR diff --git a/.github/workflows/docker-server.yml b/.github/workflows/docker-server.yml index fbf88247316..ce7b6f12165 100644 --- a/.github/workflows/docker-server.yml +++ b/.github/workflows/docker-server.yml @@ -35,7 +35,7 @@ jobs: # multi-platform images and export cache # https://github.com/docker/setup-buildx-action - name: Set up Docker Buildx - uses: docker/setup-buildx-action@c47758b77c9736f4b2ef4073d4d51994fabfe349 # v3.7.1 + uses: docker/setup-buildx-action@6524bf65af31da8d45b59e8c27de4bd072b392f5 # v3.8.0 - name: Log in to the Github Container registry uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 diff --git a/.github/workflows/docker-testbed.yml b/.github/workflows/docker-testbed.yml index c0e333781b3..8dd543a864c 100644 --- a/.github/workflows/docker-testbed.yml +++ b/.github/workflows/docker-testbed.yml @@ -44,7 +44,7 @@ jobs: # multi-platform images and export cache # https://github.com/docker/setup-buildx-action - name: Set up Docker Buildx - uses: docker/setup-buildx-action@c47758b77c9736f4b2ef4073d4d51994fabfe349 # v3.7.1 + uses: docker/setup-buildx-action@6524bf65af31da8d45b59e8c27de4bd072b392f5 # v3.8.0 - name: Log in to the Github Container registry uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 diff --git a/.github/workflows/package-cli.yml b/.github/workflows/package-cli.yml index 78fc5b903af..53fbcc2c3e1 100644 --- a/.github/workflows/package-cli.yml +++ b/.github/workflows/package-cli.yml @@ -132,7 +132,7 @@ jobs: echo "artifact_name=$FINAL_ARTIFACT_NAME" >> $GITHUB_OUTPUT timeout-minutes: 1 - - uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # pin v4.4.3 + - uses: actions/upload-artifact@6f51ac03b9356f520e9adb1b1b7802705f340c2b # pin v4.5.0 with: name: ${{ runner.os }}-${{ matrix.target }}-cli path: | diff --git a/.github/workflows/package-client.yml b/.github/workflows/package-client.yml index 498f8c22bbb..c34dae1cd09 100644 --- a/.github/workflows/package-client.yml +++ b/.github/workflows/package-client.yml @@ -108,7 +108,7 @@ jobs: working-directory: client # Install syft - - uses: taiki-e/install-action@acf70b3a1ed953bccebc8c5d80cfdb16ec8ccc36 # pin v2.46.4 + - uses: taiki-e/install-action@acd25891978b4cdaebd139d3efef606d26513b14 # pin v2.47.0 with: tool: syft@0.84.0, wasm-pack@${{ env.wasm-pack-version }} @@ -125,7 +125,7 @@ jobs: - name: Generate SBOM run: syft packages --config=.syft.yaml --output=spdx-json=client/dist/Parsec-SBOM-Web.spdx.json . - - uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # pin v4.4.3 + - uses: actions/upload-artifact@6f51ac03b9356f520e9adb1b1b7802705f340c2b # pin v4.5.0 with: name: webapp path: client/dist/ @@ -211,14 +211,14 @@ jobs: mv -v parsec_*_*.snap Parsec_${{ steps.version.outputs.full }}_linux_$ARCH.snap # Install syft - - uses: taiki-e/install-action@acf70b3a1ed953bccebc8c5d80cfdb16ec8ccc36 # pin v2.46.4 + - uses: taiki-e/install-action@acd25891978b4cdaebd139d3efef606d26513b14 # pin v2.47.0 with: tool: syft@0.84.0 - name: Generate SBOM run: syft packages --config=.syft.yaml --output=spdx-json=Parsec-SBOM-Electron-linux-snap.spdx.json . - - uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # pin v4.4.3 + - uses: actions/upload-artifact@6f51ac03b9356f520e9adb1b1b7802705f340c2b # pin v4.5.0 with: name: linux-snap-${{ runner.arch }}-electron path: | @@ -311,7 +311,7 @@ jobs: - name: Setup rust cache for debugging if: false - uses: Swatinem/rust-cache@82a92a6e8fbeee089604da2575dc567ae9ddeaab # pin v2.7.5 + uses: Swatinem/rust-cache@f0deed1e0edfc6a9be95417288c0e1099b1eeec3 # pin v2.7.7 with: cache-on-failure: true save-if: true @@ -404,7 +404,7 @@ jobs: timeout-minutes: 1 # Install syft - - uses: taiki-e/install-action@acf70b3a1ed953bccebc8c5d80cfdb16ec8ccc36 # pin v2.46.4 + - uses: taiki-e/install-action@acd25891978b4cdaebd139d3efef606d26513b14 # pin v2.47.0 with: tool: syft@0.84.0 @@ -441,7 +441,7 @@ jobs: grep -q -e "${{ steps.build-info.outputs.app_file }}" "${{ steps.build-info.outputs.latest_file }}" working-directory: client/electron/dist - - uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # pin v4.4.3 + - uses: actions/upload-artifact@6f51ac03b9356f520e9adb1b1b7802705f340c2b # pin v4.5.0 with: name: ${{ matrix.artifact_tag }}-${{ runner.arch }}-electron path: | @@ -452,7 +452,7 @@ jobs: if-no-files-found: error timeout-minutes: 10 - - uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # pin v4.4.3 + - uses: actions/upload-artifact@6f51ac03b9356f520e9adb1b1b7802705f340c2b # pin v4.5.0 if: matrix.platform == 'windows' with: name: ${{ matrix.artifact_tag }}-${{ runner.arch }}-electron-pre-built diff --git a/.github/workflows/package-server.yml b/.github/workflows/package-server.yml index 40c60265623..02d4bd172cb 100644 --- a/.github/workflows/package-server.yml +++ b/.github/workflows/package-server.yml @@ -111,14 +111,14 @@ jobs: run: python server/packaging/wheel/wheel_it.py ./server --output dist --skip-wheel # Install syft - - uses: taiki-e/install-action@acf70b3a1ed953bccebc8c5d80cfdb16ec8ccc36 # pin v2.46.4 + - uses: taiki-e/install-action@acd25891978b4cdaebd139d3efef606d26513b14 # pin v2.47.0 with: tool: syft@0.84.0 - name: Generate SBOM run: syft packages --config=.syft.yaml --output=spdx-json=dist/Parsec-SBOM-Wheel-${{ matrix.platform }}.spdx.json . - - uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # pin v4.4.3 + - uses: actions/upload-artifact@6f51ac03b9356f520e9adb1b1b7802705f340c2b # pin v4.5.0 with: name: ${{ runner.os }}-${{ runner.arch }}-wheel path: | diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 84395294a44..7cc98b8e3c4 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -140,7 +140,7 @@ jobs: - name: Publish wheel on PyPI if: steps.version.outputs.local == '' - uses: pypa/gh-action-pypi-publish@15c56dba361d8335944d31a2ecd17d700fc7bcbc # pin v1.12.2 + uses: pypa/gh-action-pypi-publish@67339c736fd9354cd4f8cb0b744f2b82a74b5c70 # pin v1.12.3 with: user: __token__ password: ${{ secrets.PYPI_CREDENTIALS }} diff --git a/.github/workflows/releaser.yml b/.github/workflows/releaser.yml index 87dee4d5f94..7aadd341600 100644 --- a/.github/workflows/releaser.yml +++ b/.github/workflows/releaser.yml @@ -221,7 +221,7 @@ jobs: - name: Create release if: github.event_name == 'schedule' || (github.event_name == 'push' && startsWith(github.ref, 'refs/tags/')) - uses: softprops/action-gh-release@01570a1f39cb168c169c802c3bceb9e93fb10974 # pin v2.1.0 + uses: softprops/action-gh-release@7b4da11513bf3f43f9999e90eabced41ab8bb048 # pin v2.2.0 with: draft: ${{ env.NIGHTLY_RELEASE != 'true' }} tag_name: ${{ github.event_name == 'schedule' && 'nightly' || github.ref }}