diff --git a/.github/workflows/build-private-images-ghcr.yml b/.github/workflows/build-private-images-ghcr.yml index 8f0d46f5a093..deaa80e2f7a0 100644 --- a/.github/workflows/build-private-images-ghcr.yml +++ b/.github/workflows/build-private-images-ghcr.yml @@ -23,7 +23,7 @@ jobs: steps: - name: Docker meta id: meta - uses: docker/metadata-action@96383f45573cb7f253c731d3b3ab81c87ef81934 # v5.0.0 + uses: docker/metadata-action@030e881283bb7a6894de51c315a6bfe6a94e05cf # v6.0.0 env: DOCKER_METADATA_PR_HEAD_SHA: true with: @@ -46,7 +46,7 @@ jobs: - name: Build and push id: docker_build - uses: useblacksmith/build-push-action@30c71162f16ea2c27c3e21523255d209b8b538c1 # v2 + uses: useblacksmith/build-push-action@fb9e3e6a9299c78462bfadd0d93352c316adc9b8 # v2 with: push: true tags: ${{ steps.meta.outputs.tags }} diff --git a/.github/workflows/build-public-images-ghcr.yml b/.github/workflows/build-public-images-ghcr.yml index 7c029247a087..7c2173fe53a8 100644 --- a/.github/workflows/build-public-images-ghcr.yml +++ b/.github/workflows/build-public-images-ghcr.yml @@ -32,12 +32,12 @@ jobs: - name: Docker meta id: meta - uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5.10.0 + uses: docker/metadata-action@030e881283bb7a6894de51c315a6bfe6a94e05cf # v6.0.0 with: images: ${{ env.GHCR_REPO }} - name: Set up Docker Buildx - uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0 + uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0 - name: Login to GitHub Container Registry uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4.1.0 @@ -68,7 +68,7 @@ jobs: touch "${{ runner.temp }}/digests/${digest#sha256:}" - name: Upload digest - uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: digests-${{ env.PLATFORM_PAIR }} path: ${{ runner.temp }}/digests/* @@ -103,9 +103,9 @@ jobs: username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - - uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0 + - uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0 - - uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5.10.0 + - uses: docker/metadata-action@030e881283bb7a6894de51c315a6bfe6a94e05cf # v6.0.0 id: meta with: images: ${{ env.GHCR_REPO }} diff --git a/.github/workflows/codespell.yml b/.github/workflows/codespell.yml index 4fdff4849edf..c8d4fd185135 100644 --- a/.github/workflows/codespell.yml +++ b/.github/workflows/codespell.yml @@ -11,7 +11,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - - uses: codespell-project/actions-codespell@406322ec52dd7b488e48c1c4b82e2a8b3a1bf630 # v2.1 + - uses: codespell-project/actions-codespell@8f01853be192eb0f849a5c7d721450e7a467c579 # v2.2 with: check_filenames: true ignore_words_file: .codespellignore diff --git a/.github/workflows/elixir.yml b/.github/workflows/elixir.yml index 48af9e9f2aec..cfdf6a637a48 100644 --- a/.github/workflows/elixir.yml +++ b/.github/workflows/elixir.yml @@ -55,14 +55,14 @@ jobs: fetch-depth: 0 filter: blob:none - - uses: marocchino/tool-versions-action@18a164fa2b0db1cc1edf7305fcb17ace36d1c306 # v1.2.0 + - uses: marocchino/tool-versions-action@4219f2e6bfdb4cce482b78f71ad9663e64f4d247 # v2.0.0 id: versions - uses: erlef/setup-beam@fc68ffb90438ef2936bbb3251622353b3dcb2f93 # v1.24.0 with: elixir-version: ${{ steps.versions.outputs.elixir }} otp-version: ${{ steps.versions.outputs.erlang }} - - uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4 + - uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 with: path: | deps @@ -155,7 +155,7 @@ jobs: fetch-depth: 0 filter: blob:none - - uses: marocchino/tool-versions-action@18a164fa2b0db1cc1edf7305fcb17ace36d1c306 # v1.2.0 + - uses: marocchino/tool-versions-action@4219f2e6bfdb4cce482b78f71ad9663e64f4d247 # v2.0.0 id: versions - uses: erlef/setup-beam@fc68ffb90438ef2936bbb3251622353b3dcb2f93 # v1.24.0 @@ -163,7 +163,7 @@ jobs: elixir-version: ${{ steps.versions.outputs.elixir }} otp-version: ${{ steps.versions.outputs.erlang }} - - uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4 + - uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 with: path: | deps @@ -179,7 +179,7 @@ jobs: e2e-${{ env.MIX_ENV }}-${{ env.CACHE_VERSION }}-refs/heads/master- - name: Cache E2E dependencies and Playwright browsers - uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4 + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 id: playwright-cache with: path: | @@ -227,7 +227,7 @@ jobs: - name: Upload E2E blob report to GitHub Actions Artifacts if: ${{ !cancelled() }} - uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: e2e-blob-report-${{ matrix.shardIndex }} path: e2e/blob-report @@ -240,7 +240,7 @@ jobs: runs-on: blacksmith-4vcpu-ubuntu-2404 steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - - uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0 + - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 with: node-version: 23.2.0 cache: 'npm' @@ -270,7 +270,7 @@ jobs: fetch-depth: 0 filter: blob:none - - uses: marocchino/tool-versions-action@18a164fa2b0db1cc1edf7305fcb17ace36d1c306 # v1.2.0 + - uses: marocchino/tool-versions-action@4219f2e6bfdb4cce482b78f71ad9663e64f4d247 # v2.0.0 id: versions - uses: erlef/setup-beam@fc68ffb90438ef2936bbb3251622353b3dcb2f93 # v1.24.0 @@ -278,7 +278,7 @@ jobs: elixir-version: ${{ steps.versions.outputs.elixir }} otp-version: ${{ steps.versions.outputs.erlang }} - - uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4 + - uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 with: path: | deps diff --git a/.github/workflows/node.yml b/.github/workflows/node.yml index c416357f7fd2..685233a76577 100644 --- a/.github/workflows/node.yml +++ b/.github/workflows/node.yml @@ -18,10 +18,10 @@ jobs: steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - name: Read .tool-versions - uses: marocchino/tool-versions-action@18a164fa2b0db1cc1edf7305fcb17ace36d1c306 # v1.2.0 + uses: marocchino/tool-versions-action@4219f2e6bfdb4cce482b78f71ad9663e64f4d247 # v2.0.0 id: versions - name: Set up Node - uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0 + uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 with: node-version: ${{steps.versions.outputs.nodejs}} - run: npm install --prefix ./assets diff --git a/.github/workflows/publish-docs.yml b/.github/workflows/publish-docs.yml index 97b3737e90e4..56987a82a3a6 100644 --- a/.github/workflows/publish-docs.yml +++ b/.github/workflows/publish-docs.yml @@ -25,7 +25,7 @@ jobs: uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - name: Read .tool-versions - uses: marocchino/tool-versions-action@18a164fa2b0db1cc1edf7305fcb17ace36d1c306 # v1.2.0 + uses: marocchino/tool-versions-action@4219f2e6bfdb4cce482b78f71ad9663e64f4d247 # v2.0.0 id: versions - name: Set up Elixir @@ -35,7 +35,7 @@ jobs: otp-version: ${{ steps.versions.outputs.erlang}} - name: Restore Elixir dependencies cache - uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4 + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 with: path: | deps diff --git a/.github/workflows/terraform-e2e.yml b/.github/workflows/terraform-e2e.yml index 8aba6bfea699..a3fbbdd36383 100644 --- a/.github/workflows/terraform-e2e.yml +++ b/.github/workflows/terraform-e2e.yml @@ -30,7 +30,7 @@ jobs: uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - name: Setup Terraform - uses: hashicorp/setup-terraform@5e8dbf3c6d9deaf4193ca7a8fb23f2ac83bb6c85 # v4.0.0 + uses: hashicorp/setup-terraform@dfe3c3f87815947d99a8997f908cb6525fc44e9e # v4.0.1 with: cli_config_credentials_token: ${{ secrets.TF_CLOUD_CHECKLY_API_TOKEN }} @@ -52,7 +52,7 @@ jobs: run: terraform plan -no-color continue-on-error: true - - uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0 + - uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 if: github.event_name == 'pull_request' env: PLAN: "terraform\n${{ steps.plan.outputs.stdout }}" diff --git a/.github/workflows/tracker-script-npm-release.yml b/.github/workflows/tracker-script-npm-release.yml index c8abec8437ea..6408649a5117 100644 --- a/.github/workflows/tracker-script-npm-release.yml +++ b/.github/workflows/tracker-script-npm-release.yml @@ -23,7 +23,7 @@ jobs: with: token: ${{ secrets.PLAUSIBLE_BOT_GITHUB_TOKEN }} - - uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0 + - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 with: node-version: 23.2.0 registry-url: 'https://registry.npmjs.org' @@ -55,7 +55,7 @@ jobs: NODE_AUTH_TOKEN: ${{ secrets.TRACKER_RELEASE_NPM_TOKEN }} - name: Commit and Push changes - uses: EndBug/add-and-commit@a94899bca583c204427a224a7af87c02f9b325d5 + uses: EndBug/add-and-commit@290ea2c423ad77ca9c62ae0f5b224379612c0321 with: message: "Released tracker script version ${{ steps.package.outputs.version }}" github_token: ${{ secrets.PLAUSIBLE_BOT_GITHUB_TOKEN }} diff --git a/.github/workflows/tracker-script-update.yml b/.github/workflows/tracker-script-update.yml index 38683ca7b9cd..44f651e9c3d6 100644 --- a/.github/workflows/tracker-script-update.yml +++ b/.github/workflows/tracker-script-update.yml @@ -71,7 +71,7 @@ jobs: fi - name: Commit and push changes - uses: EndBug/add-and-commit@a94899bca583c204427a224a7af87c02f9b325d5 + uses: EndBug/add-and-commit@290ea2c423ad77ca9c62ae0f5b224379612c0321 if: steps.increment.outputs.changed == 'true' with: message: 'chore: Bump tracker_script_version to ${{ steps.increment.outputs.version }}' @@ -121,7 +121,7 @@ jobs: - name: Get changed files id: changelog_changed - uses: tj-actions/changed-files@22103cc46bda19c2b464ffe86db46df6922fd323 + uses: tj-actions/changed-files@9426d40962ed5378910ee2e21d5f8c6fcbf2dd96 with: files: | tracker/npm_package/CHANGELOG.md diff --git a/.github/workflows/tracker.yml b/.github/workflows/tracker.yml index 9b3894ff0b3c..ab054e258561 100644 --- a/.github/workflows/tracker.yml +++ b/.github/workflows/tracker.yml @@ -21,7 +21,7 @@ jobs: shardTotal: [4] steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - - uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0 + - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 with: node-version: 23.2.0 cache: 'npm' @@ -29,7 +29,7 @@ jobs: - name: Install dependencies run: npm --prefix ./tracker ci - name: Cache Playwright browsers - uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4 + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 id: playwright-cache with: path: | @@ -49,7 +49,7 @@ jobs: run: npm --prefix ./tracker test -- --shard=${{ matrix.shardIndex }}/${{ matrix.shardTotal }} --reporter=blob - name: Upload blob report to GitHub Actions Artifacts if: ${{ !cancelled() }} - uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: blob-report-${{ matrix.shardIndex }} path: tracker/blob-report @@ -61,7 +61,7 @@ jobs: runs-on: blacksmith-4vcpu-ubuntu-2404 steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - - uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0 + - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 with: node-version: 23.2.0 cache: 'npm'