From 8bd129a53f6db77f32cf48d9966b89a3b1f8c943 Mon Sep 17 00:00:00 2001 From: Romain <96626929+Romanitho@users.noreply.github.com> Date: Mon, 30 Oct 2023 11:15:47 +0100 Subject: [PATCH 1/2] Replace pin versions to sha --- .github/workflows/WAU-AutoCreatePreVersion.yml | 8 ++++---- .github/workflows/WAU-CreateNewVersion.yml | 8 ++++---- .github/workflows/mega-linter.yml | 6 +++--- 3 files changed, 11 insertions(+), 11 deletions(-) diff --git a/.github/workflows/WAU-AutoCreatePreVersion.yml b/.github/workflows/WAU-AutoCreatePreVersion.yml index 78a4e8e..f3edb16 100644 --- a/.github/workflows/WAU-AutoCreatePreVersion.yml +++ b/.github/workflows/WAU-AutoCreatePreVersion.yml @@ -53,7 +53,7 @@ jobs: fetch-depth: 0 - name: Auto Increment Semver Action - uses: MCKanpolat/auto-semver-action@1.0.10 + uses: MCKanpolat/auto-semver-action@b0314e8d64baee1c3f74233edb71eb976503a6a4 # 1.0.10 id: versioning with: releaseType: prerelease @@ -66,14 +66,14 @@ jobs: echo "Next Release version: ${{ steps.versioning.outputs.version }}" - name: Overwrite Version.txt file - uses: DamianReeves/write-file-action@v1.2 + uses: DamianReeves/write-file-action@0a7fcbe1960c53fc08fe789fa4850d24885f4d84 # v1.2 with: path: Winget-AutoUpdate/Version.txt write-mode: overwrite contents: ${{ steps.versioning.outputs.version }} - name: Commit & Push - uses: actions-js/push@v1.4 + uses: actions-js/push@156f2b10c3aa000c44dbe75ea7018f32ae999772 # v1.4 with: github_token: ${{ secrets.GITHUB_TOKEN }} branch: main @@ -100,7 +100,7 @@ jobs: cd .. - name: Create release - uses: "ncipollo/release-action@v1" + uses: ncipollo/release-action@6c75be85e571768fa31b40abf38de58ba0397db5 # v1.13.0 id: release with: tag: "v${{ steps.versioning.outputs.version }}" diff --git a/.github/workflows/WAU-CreateNewVersion.yml b/.github/workflows/WAU-CreateNewVersion.yml index 3ce22dc..630e926 100644 --- a/.github/workflows/WAU-CreateNewVersion.yml +++ b/.github/workflows/WAU-CreateNewVersion.yml @@ -31,7 +31,7 @@ jobs: lfs: "true" - name: Auto Increment Semver Action - uses: MCKanpolat/auto-semver-action@1.0.10 + uses: MCKanpolat/auto-semver-action@b0314e8d64baee1c3f74233edb71eb976503a6a4 # 1.0.10 id: versioning with: releaseType: ${{ github.event.inputs.version }} @@ -39,14 +39,14 @@ jobs: github_token: ${{ secrets.GITHUB_TOKEN }} - name: Overwrite Version.txt file - uses: DamianReeves/write-file-action@v1.2 + uses: DamianReeves/write-file-action@0a7fcbe1960c53fc08fe789fa4850d24885f4d84 # v1.2 with: path: Winget-AutoUpdate/Version.txt write-mode: overwrite contents: "${{ steps.versioning.outputs.version }}" - name: Commit & Push - uses: actions-js/push@v1.4 + uses: actions-js/push@156f2b10c3aa000c44dbe75ea7018f32ae999772 # v1.4 with: github_token: ${{ secrets.GITHUB_TOKEN }} branch: main @@ -75,7 +75,7 @@ jobs: - name: Create release uses: "ncipollo/release-action@v1" with: - tag: "v${{ steps.versioning.outputs.version }}" + tag: ncipollo/release-action@6c75be85e571768fa31b40abf38de58ba0397db5 # v1.13.0 prerelease: ${{ github.event.inputs.pre-release }} generateReleaseNotes: true name: "v${{ steps.versioning.outputs.version }}" diff --git a/.github/workflows/mega-linter.yml b/.github/workflows/mega-linter.yml index 1655732..0492cb1 100644 --- a/.github/workflows/mega-linter.yml +++ b/.github/workflows/mega-linter.yml @@ -44,7 +44,7 @@ jobs: id: ml # You can override MegaLinter flavor used to have faster performances # More info at https://megalinter.github.io/flavors/ - uses: oxsecurity/megalinter@v7 + uses: oxsecurity/megalinter@b48455a119cc28045eee8f1e9d0a542a85e71f4f # v7.5.0 env: # All available variables are described in documentation # https://megalinter.github.io/configuration/ @@ -71,7 +71,7 @@ jobs: - name: Create Pull Request with applied fixes id: cpr if: steps.ml.outputs.has_updated_sources == 1 && (env.APPLY_FIXES_EVENT == 'all' || env.APPLY_FIXES_EVENT == github.event_name) && env.APPLY_FIXES_MODE == 'pull_request' && (github.event_name == 'push' || github.event.pull_request.head.repo.full_name == github.repository) && !contains(github.event.head_commit.message, 'skip fix') - uses: peter-evans/create-pull-request@v5 + uses: peter-evans/create-pull-request@153407881ec5c347639a548ade7d8ad1d6740e38 # v5.0.2 with: token: ${{ secrets.PAT || secrets.GITHUB_TOKEN }} commit-message: "[MegaLinter] Apply linters automatic fixes" @@ -90,7 +90,7 @@ jobs: run: sudo chown -Rc $UID .git/ - name: Commit and push applied linter fixes if: steps.ml.outputs.has_updated_sources == 1 && (env.APPLY_FIXES_EVENT == 'all' || env.APPLY_FIXES_EVENT == github.event_name) && env.APPLY_FIXES_MODE == 'commit' && github.ref != 'refs/heads/main' && (github.event_name == 'push' || github.event.pull_request.head.repo.full_name == github.repository) && !contains(github.event.head_commit.message, 'skip fix') - uses: stefanzweifel/git-auto-commit-action@v5 + uses: stefanzweifel/git-auto-commit-action@8756aa072ef5b4a080af5dc8fef36c5d586e521d # v5.0.0 with: branch: ${{ github.event.pull_request.head.ref || github.head_ref || github.ref }} commit_message: "[MegaLinter] Apply linters fixes" From fcca758a76dc6a64b4863045c897d8d79bc6f595 Mon Sep 17 00:00:00 2001 From: Romain <96626929+Romanitho@users.noreply.github.com> Date: Mon, 30 Oct 2023 11:24:19 +0100 Subject: [PATCH 2/2] copy/paste wrong place :) --- .github/workflows/WAU-CreateNewVersion.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/WAU-CreateNewVersion.yml b/.github/workflows/WAU-CreateNewVersion.yml index 630e926..b517376 100644 --- a/.github/workflows/WAU-CreateNewVersion.yml +++ b/.github/workflows/WAU-CreateNewVersion.yml @@ -73,9 +73,9 @@ jobs: cd .. - name: Create release - uses: "ncipollo/release-action@v1" + uses: ncipollo/release-action@6c75be85e571768fa31b40abf38de58ba0397db5 # v1.13.0 with: - tag: ncipollo/release-action@6c75be85e571768fa31b40abf38de58ba0397db5 # v1.13.0 + tag: "v${{ steps.versioning.outputs.version }}" prerelease: ${{ github.event.inputs.pre-release }} generateReleaseNotes: true name: "v${{ steps.versioning.outputs.version }}"