@@ -58,24 +58,24 @@ jobs:
5858
5959 steps :
6060 - name : Checkout repository
61- uses : actions/checkout@v4
61+ uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
6262
6363 - name : Set up QEMU
64- uses : docker/setup-qemu-action@v3
64+ uses : docker/setup-qemu-action@53851d14592bedcffcf25ea515637cff71ef929a # v3.3.0
6565
6666 - name : Set up Docker Buildx
67- uses : docker/setup-buildx-action@v3
67+ uses : docker/setup-buildx-action@6524bf65af31da8d45b59e8c27de4bd072b392f5 # v3.8.0
6868
6969 - name : Set up Cosign
70- uses : sigstore/cosign-installer@v3
70+ uses : sigstore/cosign-installer@dc72c7d5c4d10cd6bcb8cf6e3fd625a9e5e537da # v3.7.0
7171
7272 - name : Set image name
7373 id : image-name
7474 run : echo "value=ghcr.io/${{ github.repository }}" >> "$GITHUB_OUTPUT"
7575
7676 - name : Gather build metadata
7777 id : meta
78- uses : docker/metadata-action@v5
78+ uses : docker/metadata-action@369eb591f429131d6889c46b94e711f089e6ca96 # v5.6.1
7979 with :
8080 images : ${{ steps.image-name.outputs.value }}
8181 flavor : |
9595 # Multiple exporters are not supported yet
9696 # See https://github.com/moby/buildkit/pull/2760
9797 - name : Determine build output
98- uses : haya14busa/action-cond@v1.2.1
98+ uses : haya14busa/action-cond@94f77f7a80cd666cb3155084e428254fea4281fd # v1.2.1
9999 id : build-output
100100 with :
101101 cond : ${{ inputs.publish }}
@@ -112,7 +112,7 @@ jobs:
112112
113113 - name : Build and push image
114114 id : build
115- uses : docker/build-push-action@v6
115+ uses : docker/build-push-action@ca877d9245402d1537745e0e356eab47c3520991 # v6.13.0
116116 with :
117117 context : .
118118 platforms : linux/amd64,linux/arm64
@@ -173,14 +173,14 @@ jobs:
173173 output : trivy-results.sarif
174174
175175 - name : Upload Trivy scan results as artifact
176- uses : actions/upload-artifact@v4
176+ uses : actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
177177 with :
178178 name : " [${{ github.job }}] Trivy scan results"
179179 path : trivy-results.sarif
180180 retention-days : 5
181181
182182 - name : Upload Trivy scan results to GitHub Security tab
183- uses : github/codeql-action/upload-sarif@df409f7d9260372bd5f19e5b04e83cb3c43714ae # v3.27.9
183+ uses : github/codeql-action/upload-sarif@dd746615b3b9d728a6a37ca2045b68ca76d4841a # v3.28.8
184184 with :
185185 sarif_file : trivy-results.sarif
186186
@@ -201,13 +201,13 @@ jobs:
201201
202202 steps :
203203 - name : Checkout repository
204- uses : actions/checkout@v4
204+ uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
205205
206206 - name : Set up Helm
207- uses : azure/setup-helm@v4.2.0
207+ uses : azure/setup-helm@fe7b79cd5ee1e45176fcad797de68ecaf3ca4814 # v4.2.0
208208
209209 - name : Set up Cosign
210- uses : sigstore/cosign-installer@v3
210+ uses : sigstore/cosign-installer@dc72c7d5c4d10cd6bcb8cf6e3fd625a9e5e537da # v3.7.0
211211
212212 - name : Set chart name
213213 id : chart-name
@@ -242,7 +242,7 @@ jobs:
242242 echo "package=${{ steps.chart-name.outputs.value }}-${{ steps.version.outputs.value }}.tgz" >> "$GITHUB_OUTPUT"
243243
244244 - name : Upload chart as artifact
245- uses : actions/upload-artifact@v4
245+ uses : actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
246246 with :
247247 name : " [${{ github.job }}] Helm chart"
248248 path : ${{ steps.build.outputs.package }}
@@ -292,13 +292,13 @@ jobs:
292292 output : trivy-results.sarif
293293
294294 - name : Upload Trivy scan results as artifact
295- uses : actions/upload-artifact@v4
295+ uses : actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
296296 with :
297297 name : " [${{ github.job }}] Trivy scan results"
298298 path : trivy-results.sarif
299299 retention-days : 5
300300
301301 - name : Upload Trivy scan results to GitHub Security tab
302- uses : github/codeql-action/upload-sarif@df409f7d9260372bd5f19e5b04e83cb3c43714ae # v3.27.9
302+ uses : github/codeql-action/upload-sarif@dd746615b3b9d728a6a37ca2045b68ca76d4841a # v3.28.8
303303 with :
304304 sarif_file : trivy-results.sarif
0 commit comments