2828 attestations : write
2929 id-token : write
3030 steps :
31- - uses : actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4
31+ - uses : actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
3232 with :
3333 fetch-depth : 0
3434
5353
5454 - name : Install uv
5555 if : ${{ steps.changed.outcome == 'success' }}
56- uses : astral-sh/setup-uv@bd01e18f51369d5a26f1651c3cb451d3417e3bba # v6
56+ uses : astral-sh/setup-uv@d0cc045d04ccac9d8b7881df0226f9e82c39688e # v6.8.0
5757
5858 - name : Bump version in files
5959 if : ${{ steps.changed.outcome == 'success' }}
@@ -73,17 +73,17 @@ jobs:
7373 CUSTOM_TAG : ${{ steps.version.outputs.new_tag }}
7474
7575 - name : Log in to the Container registry
76- uses : docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3
76+ uses : docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3.6.0
7777 with :
7878 registry : ${{ env.REGISTRY }}
7979 username : ${{ github.actor }}
8080 password : ${{ secrets.GITHUB_TOKEN }}
8181
8282 - name : Set up QEMU
83- uses : docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3
83+ uses : docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3.6.0
8484
8585 - name : Set up Docker Buildx
86- uses : docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3
86+ uses : docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
8787
8888 - name : Generate metadata for published image
8989 id : meta
9494
9595 - name : Build and push Docker image
9696 id : push
97- uses : docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6
97+ uses : docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18.0
9898 with :
9999 context : src/
100100 platforms : linux/amd64,linux/arm64
@@ -112,15 +112,15 @@ jobs:
112112 org.opencontainers.image.created=${{ steps.meta.outputs.timestamp }}
113113
114114 - name : Generate artifact attestation
115- uses : actions/attest-build-provenance@e8998f949152b193b063cb0ec769d69d929409be # v2
115+ uses : actions/attest-build-provenance@e8998f949152b193b063cb0ec769d69d929409be # v2.4.0
116116 with :
117117 subject-name : ${{ env.REGISTRY }}/${{ env.IMAGE_NAME}}
118118 subject-digest : ${{ steps.push.outputs.digest }}
119119 push-to-registry : true
120120
121121 - name : Update release
122122 if : ${{ steps.changed.outcome == 'success' }}
123- uses : ncipollo/release-action@bcfe5470707e8832e12347755757cec0eb3c22af # v1
123+ uses : ncipollo/release-action@b7eabc95ff50cbeeedec83973935c8f306dfcd0b # v1.20.0
124124 with :
125125 allowUpdates : true
126126 updateOnlyUnreleased : true
0 commit comments