Skip to content
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.

Commit 27625c0

Browse files
renovate[bot]nijel
authored andcommittedFeb 19, 2025·
chore(deps): pin dependencies
1 parent b2c2445 commit 27625c0

9 files changed

+43
-43
lines changed
 

‎.github/workflows/container-build.yml

+6-6
Original file line numberDiff line numberDiff line change
@@ -23,16 +23,16 @@ jobs:
2323
env:
2424
MATRIX_ARCHITECTURE: ${{ inputs.architecture }}
2525
steps:
26-
- uses: actions/checkout@v4
26+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
2727
- name: Set up QEMU
2828
if: inputs.architecture != 'linux/amd64' && inputs.architecture != 'linux/arm64'
29-
uses: docker/setup-qemu-action@v3.4.0
29+
uses: docker/setup-qemu-action@4574d27a4764455b42196d70a065bc6853246a25 # v3.4.0
3030
with:
3131
platforms: ${{ inputs.architecture }}
3232
- name: Expose GitHub Runtime
33-
uses: crazy-max/ghaction-github-runtime@v3
33+
uses: crazy-max/ghaction-github-runtime@b3a9207c0e1ef41f4cf215303c976869d0c2c1c4 # v3
3434
- name: Set up Docker Buildx
35-
uses: docker/setup-buildx-action@v3.9.0
35+
uses: docker/setup-buildx-action@f7ce87c1d6bead3e36075b2ce75da1f6cc28aaca # v3.9.0
3636
with:
3737
# renovate: datasource=github-releases depName=docker/buildx
3838
version: v0.20.1
@@ -42,13 +42,13 @@ jobs:
4242
- name: Configure Docker build
4343
run: .github/bin/get-buildx-args
4444
- name: Cache
45-
uses: actions/cache@v4
45+
uses: actions/cache@0c907a75c2c80ebcb7f088228285e798b750cf8f # v4
4646
id: cache
4747
with:
4848
path: uv-cache
4949
key: uv-cache-${{ hashFiles('Dockerfile') }}-${{ inputs.architecture }}
5050
- name: inject cache into docker
51-
uses: reproducible-containers/buildkit-cache-dance@v3.1.2
51+
uses: reproducible-containers/buildkit-cache-dance@5b6db76d1da5c8b307d5d2e0706d266521b710de # v3.1.2
5252
with:
5353
cache-map: |
5454
{

‎.github/workflows/container-ci.yml

+26-26
Original file line numberDiff line numberDiff line change
@@ -131,11 +131,11 @@ jobs:
131131
env:
132132
MATRIX_ARCHITECTURE: linux/amd64
133133
steps:
134-
- uses: actions/checkout@v4
134+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
135135
- name: Expose GitHub Runtime
136-
uses: crazy-max/ghaction-github-runtime@v3
136+
uses: crazy-max/ghaction-github-runtime@b3a9207c0e1ef41f4cf215303c976869d0c2c1c4 # v3
137137
- name: Set up Docker Buildx
138-
uses: docker/setup-buildx-action@v3.9.0
138+
uses: docker/setup-buildx-action@f7ce87c1d6bead3e36075b2ce75da1f6cc28aaca # v3.9.0
139139
with:
140140
# renovate: datasource=github-releases depName=docker/buildx
141141
version: v0.20.1
@@ -147,15 +147,15 @@ jobs:
147147
- name: List Docker images
148148
run: docker image ls --all
149149
- name: Checkout the code
150-
uses: actions/checkout@v4
150+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
151151
- name: Anchore scan action
152-
uses: anchore/scan-action@v6
152+
uses: anchore/scan-action@7c05671ae9be166aeb155bad2d7df9121823df32 # v6
153153
id: scan
154154
with:
155155
image: weblate/weblate:test
156156
fail-build: false
157157
- name: Upload Anchore Scan Report
158-
uses: github/codeql-action/upload-sarif@v3
158+
uses: github/codeql-action/upload-sarif@9e8d0789d4a0fa9ceb6b1738f7e269594bdd67f0 # v3
159159
with:
160160
sarif_file: ${{ steps.scan.outputs.sarif }}
161161

@@ -170,11 +170,11 @@ jobs:
170170
env:
171171
MATRIX_ARCHITECTURE: linux/amd64
172172
steps:
173-
- uses: actions/checkout@v4
173+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
174174
- name: Expose GitHub Runtime
175-
uses: crazy-max/ghaction-github-runtime@v3
175+
uses: crazy-max/ghaction-github-runtime@b3a9207c0e1ef41f4cf215303c976869d0c2c1c4 # v3
176176
- name: Set up Docker Buildx
177-
uses: docker/setup-buildx-action@v3.9.0
177+
uses: docker/setup-buildx-action@f7ce87c1d6bead3e36075b2ce75da1f6cc28aaca # v3.9.0
178178
with:
179179
# renovate: datasource=github-releases depName=docker/buildx
180180
version: v0.20.1
@@ -186,9 +186,9 @@ jobs:
186186
- name: List Docker images
187187
run: docker image ls --all
188188
- name: Checkout the code
189-
uses: actions/checkout@v4
189+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
190190
- name: Run Trivy vulnerability scanner
191-
uses: aquasecurity/trivy-action@0.29.0
191+
uses: aquasecurity/trivy-action@18f2510ee396bbf400402947b394f2dd8c87dbb0 # 0.29.0
192192
env:
193193
TRIVY_DB_REPOSITORY: public.ecr.aws/aquasecurity/trivy-db:2
194194
with:
@@ -199,10 +199,10 @@ jobs:
199199
severity: CRITICAL,HIGH
200200

201201
- name: Upload Trivy scan results to GitHub Security tab
202-
uses: github/codeql-action/upload-sarif@v3
202+
uses: github/codeql-action/upload-sarif@9e8d0789d4a0fa9ceb6b1738f7e269594bdd67f0 # v3
203203
with:
204204
sarif_file: trivy-results.sarif
205-
- uses: actions/upload-artifact@v4
205+
- uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4
206206
with:
207207
name: Trivy scan SARIF
208208
path: trivy-results.sarif
@@ -216,15 +216,15 @@ jobs:
216216
- revisions
217217
steps:
218218
- name: Checkout
219-
uses: actions/checkout@v4
219+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
220220
- name: Set up QEMU
221-
uses: docker/setup-qemu-action@v3.4.0
221+
uses: docker/setup-qemu-action@4574d27a4764455b42196d70a065bc6853246a25 # v3.4.0
222222
with:
223223
platforms: all
224224
- name: Expose GitHub Runtime
225-
uses: crazy-max/ghaction-github-runtime@v3
225+
uses: crazy-max/ghaction-github-runtime@b3a9207c0e1ef41f4cf215303c976869d0c2c1c4 # v3
226226
- name: Set up Docker Buildx
227-
uses: docker/setup-buildx-action@v3.9.0
227+
uses: docker/setup-buildx-action@f7ce87c1d6bead3e36075b2ce75da1f6cc28aaca # v3.9.0
228228
with:
229229
# renovate: datasource=github-releases depName=docker/buildx
230230
version: v0.20.1
@@ -264,15 +264,15 @@ jobs:
264264
if: ${{ (startsWith(github.ref, 'refs/tags/') || (github.ref == 'refs/heads/main')) && github.repository == 'WeblateOrg/docker' }}
265265
steps:
266266
- name: Checkout
267-
uses: actions/checkout@v4
267+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
268268
- name: Set up QEMU
269-
uses: docker/setup-qemu-action@v3.4.0
269+
uses: docker/setup-qemu-action@4574d27a4764455b42196d70a065bc6853246a25 # v3.4.0
270270
with:
271271
platforms: all
272272
- name: Expose GitHub Runtime
273-
uses: crazy-max/ghaction-github-runtime@v3
273+
uses: crazy-max/ghaction-github-runtime@b3a9207c0e1ef41f4cf215303c976869d0c2c1c4 # v3
274274
- name: Set up Docker Buildx
275-
uses: docker/setup-buildx-action@v3.9.0
275+
uses: docker/setup-buildx-action@f7ce87c1d6bead3e36075b2ce75da1f6cc28aaca # v3.9.0
276276
with:
277277
# renovate: datasource=github-releases depName=docker/buildx
278278
version: v0.20.1
@@ -303,21 +303,21 @@ jobs:
303303
DOCKER_IMAGE: ghcr.io/weblateorg/weblate
304304
steps:
305305
- name: Checkout
306-
uses: actions/checkout@v4
306+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
307307
- name: Set up QEMU
308-
uses: docker/setup-qemu-action@v3.4.0
308+
uses: docker/setup-qemu-action@4574d27a4764455b42196d70a065bc6853246a25 # v3.4.0
309309
with:
310310
platforms: all
311311
- name: Expose GitHub Runtime
312-
uses: crazy-max/ghaction-github-runtime@v3
312+
uses: crazy-max/ghaction-github-runtime@b3a9207c0e1ef41f4cf215303c976869d0c2c1c4 # v3
313313
- name: Set up Docker Buildx
314-
uses: docker/setup-buildx-action@v3.9.0
314+
uses: docker/setup-buildx-action@f7ce87c1d6bead3e36075b2ce75da1f6cc28aaca # v3.9.0
315315
with:
316316
# renovate: datasource=github-releases depName=docker/buildx
317317
version: v0.20.1
318318
- name: Login to GitHub Container Registry
319319
if: ${{ github.event_name != 'pull_request'}}
320-
uses: docker/login-action@v3
320+
uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3
321321
with:
322322
registry: ghcr.io
323323
username: ${{ github.actor }}

‎.github/workflows/container-test.yml

+3-3
Original file line numberDiff line numberDiff line change
@@ -32,13 +32,13 @@ jobs:
3232
PYTHONUNBUFFERED: 1
3333
TEST_CONTAINER: weblate/weblate:test
3434
steps:
35-
- uses: actions/checkout@v4
35+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
3636
with:
3737
submodules: recursive
3838
- name: Expose GitHub Runtime
39-
uses: crazy-max/ghaction-github-runtime@v3
39+
uses: crazy-max/ghaction-github-runtime@b3a9207c0e1ef41f4cf215303c976869d0c2c1c4 # v3
4040
- name: Set up Docker Buildx
41-
uses: docker/setup-buildx-action@v3.9.0
41+
uses: docker/setup-buildx-action@f7ce87c1d6bead3e36075b2ce75da1f6cc28aaca # v3.9.0
4242
with:
4343
# renovate: datasource=github-releases depName=docker/buildx
4444
version: v0.20.1

‎.github/workflows/dockerimage.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -35,6 +35,6 @@ jobs:
3535
- ci
3636
if: ${{ startsWith(github.ref, 'refs/tags/') && github.repository == 'WeblateOrg/docker' }}
3737
steps:
38-
- uses: ncipollo/release-action@v1
38+
- uses: ncipollo/release-action@cdcc88a9acf3ca41c16c37bb7d21b9ad48560d87 # v1
3939
with:
4040
generateReleaseNotes: true

‎.github/workflows/hadolint.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -22,5 +22,5 @@ jobs:
2222
runs-on: ubuntu-24.04
2323

2424
steps:
25-
- uses: actions/checkout@v4
26-
- uses: hadolint/hadolint-action@v3.1.0
25+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
26+
- uses: hadolint/hadolint-action@54c9adbab1582c2ef04b2016b760714a4bfde3cf # v3.1.0

‎.github/workflows/label-sync.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ jobs:
2121
name: Sync labels
2222
runs-on: ubuntu-24.04
2323
steps:
24-
- uses: actions/checkout@v4 # v4
24+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
2525
- uses: srealmoreno/label-sync-action@850ba5cef2b25e56c6c420c4feed0319294682fd # v2
2626
with:
2727
clean-labels: true

‎.github/workflows/pre-commit.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ jobs:
2020
runs-on: ubuntu-24.04
2121

2222
steps:
23-
- uses: actions/checkout@v4 # v4
23+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
2424
- uses: actions/cache@0c907a75c2c80ebcb7f088228285e798b750cf8f # v4
2525
with:
2626
path: ~/.cache/pre-commit

‎.github/workflows/readme-sync.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -16,9 +16,9 @@ jobs:
1616
if: ${{ github.repository == 'WeblateOrg/docker'}}
1717
steps:
1818
- name: Checkout
19-
uses: actions/checkout@v4
19+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
2020
- name: Docker Hub Description
21-
uses: peter-evans/dockerhub-description@v4
21+
uses: peter-evans/dockerhub-description@e98e4d1628a5f3be2be7c231e50981aee98723ae # v4
2222
with:
2323
username: ${{ secrets.DOCKERHUB_USERNAME }}
2424
password: ${{ secrets.DOCKERHUB_PASSWORD }}

‎.github/workflows/semgrep.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ jobs:
2020
container:
2121
image: returntocorp/semgrep
2222
steps:
23-
- uses: actions/checkout@v4
23+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
2424
- run: semgrep ci
2525
permissions:
2626
contents: read

0 commit comments

Comments
 (0)
Please sign in to comment.