diff --git a/.github/workflows/backend.yml b/.github/workflows/backend.yml index cc820c3..76cdcd1 100644 --- a/.github/workflows/backend.yml +++ b/.github/workflows/backend.yml @@ -34,7 +34,7 @@ jobs: backend: ${{ steps.changes.outputs.backend }} steps: - uses: actions/checkout@v7 - - uses: dorny/paths-filter@fbd0ab8f3e69293af611ebaee6363fc25e6d187d # v4.0.1 + - uses: dorny/paths-filter@ceb8a2b8f2d89434be7ff52d3de7ec3738c5cc9d # v4.0.3 id: changes with: filters: | @@ -66,7 +66,7 @@ jobs: - uses: actions/checkout@v7 - name: Setup .NET (from global.json) - uses: actions/setup-dotnet@v5 + uses: actions/setup-dotnet@v6 with: global-json-file: global.json @@ -128,7 +128,7 @@ jobs: # Turn the cobertura output (from coverlet.collector) into a markdown table on the run's summary page. - name: Coverage summary if: ${{ !cancelled() }} - uses: danielpalme/ReportGenerator-GitHub-Action@049f7ec958c672fd31d5cc1cb01622dc8d2e23ab # 5 + uses: danielpalme/ReportGenerator-GitHub-Action@d3ebf1f760f7d8ab92cc44d9bcfee7ad73722a31 # 5 with: reports: ${{ github.workspace }}/TestResults/**/coverage.cobertura.xml targetdir: ${{ github.workspace }}/coveragereport @@ -167,7 +167,7 @@ jobs: - uses: actions/checkout@v7 - name: Setup .NET (from global.json) - uses: actions/setup-dotnet@v5 + uses: actions/setup-dotnet@v6 with: global-json-file: global.json diff --git a/.github/workflows/dependabot-auto-merge.yml b/.github/workflows/dependabot-auto-merge.yml index eb1ca1c..bf4317e 100644 --- a/.github/workflows/dependabot-auto-merge.yml +++ b/.github/workflows/dependabot-auto-merge.yml @@ -27,7 +27,7 @@ jobs: steps: - name: Fetch Dependabot metadata id: metadata - uses: dependabot/fetch-metadata@21025c705c08248db411dc16f3619e6b5f9ea21a # v2.5.0 + uses: dependabot/fetch-metadata@25dd0e34f4fe68f24cc83900b1fe3fe149efef98 # v3.1.0 with: github-token: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/deploy-aws.yml b/.github/workflows/deploy-aws.yml index 29dd4b5..2cc8739 100644 --- a/.github/workflows/deploy-aws.yml +++ b/.github/workflows/deploy-aws.yml @@ -78,7 +78,7 @@ jobs: - uses: actions/checkout@v7 - name: Configure AWS credentials (OIDC) - uses: aws-actions/configure-aws-credentials@254c19bd240aabef8777f48595e9d2d7b972184b # v6.2.1 + uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3 with: role-to-assume: ${{ vars.AWS_ROLE_ARN }} aws-region: ${{ env.AWS_REGION }} @@ -88,10 +88,10 @@ jobs: uses: aws-actions/amazon-ecr-login@d539f0932e70871a027e9d5a9d8fc38589180a64 # v2 - name: Set up Buildx - uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4 + uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4 - name: Build & push ${{ matrix.repo }} - uses: docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7 + uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7 with: context: ${{ matrix.context }} file: ${{ matrix.dockerfile }} @@ -113,7 +113,7 @@ jobs: - uses: actions/checkout@v7 - name: Configure AWS credentials (OIDC) - uses: aws-actions/configure-aws-credentials@254c19bd240aabef8777f48595e9d2d7b972184b # v6.2.1 + uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3 with: role-to-assume: ${{ vars.AWS_ROLE_ARN }} aws-region: ${{ env.AWS_REGION }} diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml index 5b49a75..7a9aa5b 100644 --- a/.github/workflows/docker.yml +++ b/.github/workflows/docker.yml @@ -44,7 +44,7 @@ jobs: steps: - uses: actions/checkout@v7 - - uses: dorny/paths-filter@fbd0ab8f3e69293af611ebaee6363fc25e6d187d # v4.0.1 + - uses: dorny/paths-filter@ceb8a2b8f2d89434be7ff52d3de7ec3738c5cc9d # v4.0.3 id: changes with: filters: | diff --git a/.github/workflows/e2e.yml b/.github/workflows/e2e.yml index 1cd8a72..38bf428 100644 --- a/.github/workflows/e2e.yml +++ b/.github/workflows/e2e.yml @@ -45,7 +45,7 @@ jobs: - uses: actions/checkout@v7 - name: Setup Node 20 - uses: actions/setup-node@v6 + uses: actions/setup-node@v7 with: node-version: 20 cache: npm diff --git a/.github/workflows/frontend.yml b/.github/workflows/frontend.yml index 6442e17..6e50d2d 100644 --- a/.github/workflows/frontend.yml +++ b/.github/workflows/frontend.yml @@ -27,7 +27,7 @@ jobs: matrix: ${{ steps.set.outputs.matrix }} steps: - uses: actions/checkout@v7 - - uses: dorny/paths-filter@fbd0ab8f3e69293af611ebaee6363fc25e6d187d # v4.0.1 + - uses: dorny/paths-filter@ceb8a2b8f2d89434be7ff52d3de7ec3738c5cc9d # v4.0.3 id: changes with: filters: | @@ -70,7 +70,7 @@ jobs: - uses: actions/checkout@v7 - name: Setup Node 20 - uses: actions/setup-node@v6 + uses: actions/setup-node@v7 with: node-version: 20 cache: npm diff --git a/.github/workflows/labeler.yml b/.github/workflows/labeler.yml index 2fa638b..bd951ce 100644 --- a/.github/workflows/labeler.yml +++ b/.github/workflows/labeler.yml @@ -19,6 +19,6 @@ jobs: contents: read pull-requests: write steps: - - uses: actions/labeler@v6 + - uses: actions/labeler@v7 with: sync-labels: true diff --git a/.github/workflows/publish-image.yml b/.github/workflows/publish-image.yml index b63db9c..2b738ef 100644 --- a/.github/workflows/publish-image.yml +++ b/.github/workflows/publish-image.yml @@ -49,10 +49,10 @@ jobs: # QEMU lets the amd64 runner cross-build the arm64 image (Graviton on ECS is cheaper). - name: Setup QEMU if: env.PUSH == 'true' - uses: docker/setup-qemu-action@06116385d9baf250c9f4dcb4858b16962ea869c3 # v4.1.0 + uses: docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v4.2.0 - name: Setup Buildx - uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4 + uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4 - name: Compute tags & metadata id: meta @@ -79,7 +79,7 @@ jobs: - name: Log in to GHCR if: env.PUSH == 'true' - uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4.2.0 + uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 with: registry: ghcr.io username: ${{ github.actor }} @@ -87,7 +87,7 @@ jobs: - name: Build & push id: build - uses: docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7 + uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7 with: context: ${{ inputs.context }} file: ${{ inputs.dockerfile }}