Skip to content

Commit 36e4dc3

Browse files
chore(deps): pin dependencies (main) (#36)
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [Baker-scripts/.github](https://redirect.github.com/Baker-scripts/.github) | action | pinDigest | → `24bddc3` | | [actions/upload-artifact](https://redirect.github.com/actions/upload-artifact) | action | pinDigest | → `043fb46` | | [anchore/sbom-action](https://redirect.github.com/anchore/sbom-action) | action | pinDigest | → `e22c389` | | [aquasecurity/trivy-action](https://redirect.github.com/aquasecurity/trivy-action) | action | pinDigest | → `ed142fd` | | [docker/build-push-action](https://redirect.github.com/docker/build-push-action) | action | pinDigest | → `f9f3042` | | [docker/login-action](https://redirect.github.com/docker/login-action) | action | pinDigest | → `650006c` | | [docker/metadata-action](https://redirect.github.com/docker/metadata-action) | action | pinDigest | → `80c7e94` | | [docker/setup-buildx-action](https://redirect.github.com/docker/setup-buildx-action) | action | pinDigest | → `d7f5e7f` | | [github/codeql-action](https://redirect.github.com/github/codeql-action) | action | pinDigest | → `8aad20d` | --- ### Configuration 📅 **Schedule**: (in timezone America/Chicago) - Branch creation - "before 6am on sunday" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://redirect.github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/baker-scripts/RedditModLog). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNDIuMiIsInVwZGF0ZWRJblZlciI6IjQzLjI0Mi4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiLCJyZW5vdmF0ZSJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
1 parent 08fb4f1 commit 36e4dc3

2 files changed

Lines changed: 9 additions & 9 deletions

File tree

‎.github/workflows/docker-build.yml‎

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -46,19 +46,19 @@ jobs:
4646
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
4747

4848
- name: Set up Docker Buildx
49-
uses: docker/setup-buildx-action@v4
49+
uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4
5050

5151
- name: Log in to GitHub Container Registry
5252
if: github.event_name != 'pull_request'
53-
uses: docker/login-action@v4
53+
uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4
5454
with:
5555
registry: ${{ env.REGISTRY }}
5656
username: ${{ github.actor }}
5757
password: ${{ secrets.GITHUB_TOKEN }}
5858

5959
- name: Extract metadata
6060
id: meta
61-
uses: docker/metadata-action@v6
61+
uses: docker/metadata-action@80c7e94dd9b9319bd5eb7a0e0fe9291e23a2a2e9 # v6
6262
with:
6363
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
6464
tags: |
@@ -76,7 +76,7 @@ jobs:
7676
org.opencontainers.image.licenses=GPL-3.0
7777
7878
- name: Build and push Docker image
79-
uses: docker/build-push-action@v7
79+
uses: docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7
8080
with:
8181
context: .
8282
platforms: linux/amd64,linux/arm64
@@ -92,15 +92,15 @@ jobs:
9292
9393
- name: Generate SBOM
9494
if: github.event_name != 'pull_request'
95-
uses: anchore/sbom-action@v0
95+
uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0
9696
with:
9797
image: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ steps.meta.outputs.version }}
9898
format: spdx-json
9999
output-file: sbom.spdx.json
100100

101101
- name: Upload SBOM
102102
if: github.event_name != 'pull_request'
103-
uses: actions/upload-artifact@v7
103+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
104104
with:
105105
name: sbom
106106
path: sbom.spdx.json
@@ -116,14 +116,14 @@ jobs:
116116

117117
steps:
118118
- name: Run Trivy vulnerability scanner
119-
uses: aquasecurity/trivy-action@v0.36.0
119+
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
120120
with:
121121
image-ref: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ needs.build.outputs.image-tag }}
122122
format: 'sarif'
123123
output: 'trivy-results.sarif'
124124

125125
- name: Upload Trivy results to GitHub Security tab
126-
uses: github/codeql-action/upload-sarif@v4
126+
uses: github/codeql-action/upload-sarif@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4
127127
if: always()
128128
with:
129129
sarif_file: 'trivy-results.sarif'

‎.github/workflows/pre-commit.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,4 +9,4 @@ name: Pre-commit
99

1010
jobs:
1111
pre-commit:
12-
uses: Baker-scripts/.github/.github/workflows/pre-commit.yml@main
12+
uses: Baker-scripts/.github/.github/workflows/pre-commit.yml@24bddc386063122294bd55f4f965f2620ccb10c3 # main

0 commit comments

Comments
 (0)