diff --git a/.github/workflows/codeql.yaml b/.github/workflows/codeql.yaml index 1c51b9e7ca..2d2241e5a4 100644 --- a/.github/workflows/codeql.yaml +++ b/.github/workflows/codeql.yaml @@ -42,7 +42,7 @@ jobs: uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL - uses: github/codeql-action/init@6f5948dfacef28e207b48d0905cf90c03365536d # v3.37.9 + uses: github/codeql-action/init@1190a975f95ce23525efb6a3fc21ea29567c1b52 # v3.38.2 with: languages: ${{ matrix.language }} # If you wish to specify custom queries, you can do so here or in a config file. @@ -53,7 +53,7 @@ jobs: # Autobuild attempts to build any compiled languages (C/C++, C#, Go, or Java). # If this step fails, then you should remove it and run the build manually (see below) - name: Autobuild - uses: github/codeql-action/autobuild@6f5948dfacef28e207b48d0905cf90c03365536d # v3.37.9 + uses: github/codeql-action/autobuild@1190a975f95ce23525efb6a3fc21ea29567c1b52 # v3.38.2 # â„šī¸ Command-line programs to run using the OS shell. # 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun # If the Autobuild fails above, remove it and uncomment the following three lines. @@ -62,6 +62,6 @@ jobs: # echo "Run, Build Application using script" # ./location_of_script_within_repo/buildscript.sh - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@6f5948dfacef28e207b48d0905cf90c03365536d # v3.37.9 + uses: github/codeql-action/analyze@1190a975f95ce23525efb6a3fc21ea29567c1b52 # v3.38.2 with: category: '/language:${{matrix.language}}' diff --git a/.github/workflows/coverage-baseline.yml b/.github/workflows/coverage-baseline.yml index e606a8f87c..5ba0cb29c7 100644 --- a/.github/workflows/coverage-baseline.yml +++ b/.github/workflows/coverage-baseline.yml @@ -63,7 +63,7 @@ jobs: run: rm app-config.yaml && mv app-config.example.yaml app-config.yaml - name: Install dependencies - uses: backstage/actions/yarn-install@0d281eb2e96927466db49d4cd01d52b14809a66b # v0.7.10 + uses: backstage/actions/yarn-install@a9e1b58ad52aaf319264e18c3ff6887a4c824b52 # v0.7.13 with: cache-prefix: ${{ runner.os }}-${{ hashFiles('.nvmrc') }} diff --git a/.github/workflows/pr.yaml b/.github/workflows/pr.yaml index 57cedb6130..a198118dd2 100644 --- a/.github/workflows/pr.yaml +++ b/.github/workflows/pr.yaml @@ -69,7 +69,7 @@ jobs: - name: Install dependencies if: ${{ steps.check-image.outputs.is_skipped != 'true' }} - uses: backstage/actions/yarn-install@0d281eb2e96927466db49d4cd01d52b14809a66b # v0.7.10 + uses: backstage/actions/yarn-install@a9e1b58ad52aaf319264e18c3ff6887a4c824b52 # v0.7.13 with: cache-prefix: ${{ runner.os }}-${{ hashFiles('.nvmrc') }} @@ -118,7 +118,7 @@ jobs: - name: Install dependencies if: ${{ steps.check-image.outputs.is_skipped != 'true' }} - uses: backstage/actions/yarn-install@0d281eb2e96927466db49d4cd01d52b14809a66b # v0.7.10 + uses: backstage/actions/yarn-install@a9e1b58ad52aaf319264e18c3ff6887a4c824b52 # v0.7.13 with: cache-prefix: ${{ runner.os }}-${{ hashFiles('.nvmrc') }} @@ -200,7 +200,7 @@ jobs: - name: Install dependencies if: ${{ steps.bump.outputs.run_bump_checks == 'true' }} - uses: backstage/actions/yarn-install@0d281eb2e96927466db49d4cd01d52b14809a66b # v0.7.10 + uses: backstage/actions/yarn-install@a9e1b58ad52aaf319264e18c3ff6887a4c824b52 # v0.7.13 with: cache-prefix: ${{ runner.os }}-${{ hashFiles('.nvmrc') }} diff --git a/.github/workflows/toml-checks.yaml b/.github/workflows/toml-checks.yaml index 7c7ad3d264..86e1f1decc 100644 --- a/.github/workflows/toml-checks.yaml +++ b/.github/workflows/toml-checks.yaml @@ -13,7 +13,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 - - uses: tombi-toml/setup-tombi@4944e8c74b386b05a1121e2c4155f21380ae35d5 # v1.5.3 + - uses: tombi-toml/setup-tombi@adc72e7b9a4c5fc8beac71a944c0cc52edbe06f5 # v1.6.1 with: version: 'v0.9.9' checksum: 'b50dbc90ec27591dbaf564b628bd3b3e4ead371a60931bc8ea5f34d7cd1d3607' diff --git a/.github/workflows/update-backstage.yaml b/.github/workflows/update-backstage.yaml index 5d12c433bd..aaf4112fd9 100644 --- a/.github/workflows/update-backstage.yaml +++ b/.github/workflows/update-backstage.yaml @@ -61,7 +61,7 @@ jobs: registry-url: 'https://registry.npmjs.org' - name: Install dependencies - uses: backstage/actions/yarn-install@0d281eb2e96927466db49d4cd01d52b14809a66b # v0.7.10 + uses: backstage/actions/yarn-install@a9e1b58ad52aaf319264e18c3ff6887a4c824b52 # v0.7.13 with: cache-prefix: ${{ runner.os }}-v20