From c9aee02688ca080d4f371ffd6e6fea4cd137d6a8 Mon Sep 17 00:00:00 2001
From: "renovate-pagopa[bot]"
 <164534245+renovate-pagopa[bot]@users.noreply.github.com>
Date: Wed, 4 Dec 2024 05:51:57 +0000
Subject: [PATCH] Pin dependencies

---
 .github/workflows/anchore.yml           |  6 +++---
 .github/workflows/check_pr.yml          | 10 +++++-----
 .github/workflows/code_review.yml       |  4 ++--
 .github/workflows/create_dashboard.yaml |  4 ++--
 .github/workflows/integration_test.yml  |  4 ++--
 .github/workflows/release_deploy.yml    |  4 ++--
 .github/workflows/update_code.yml       |  6 +++---
 .github/workflows/update_infra.yml      |  2 +-
 Dockerfile                              |  2 +-
 9 files changed, 21 insertions(+), 21 deletions(-)

diff --git a/.github/workflows/anchore.yml b/.github/workflows/anchore.yml
index 802f626..7904263 100644
--- a/.github/workflows/anchore.yml
+++ b/.github/workflows/anchore.yml
@@ -35,20 +35,20 @@ jobs:
     runs-on: ubuntu-latest
     steps:
       - name: Checkout the code
-        uses: actions/checkout@v3
+        uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # v3
 
       - name: Build the Docker image
         run: docker build . --file ${{ env.DOCKERFILE }} --tag localbuild/testimage:latest
 
       - name: Run the Anchore scan action itself with GitHub Advanced Security code scanning integration enabled
-        uses: anchore/scan-action@v3
+        uses: anchore/scan-action@3343887d815d7b07465f6fdcd395bd66508d486a # v3
         with:
           image: "localbuild/testimage:latest"
           acs-report-enable: true
           fail-build: true
           severity-cutoff: "high"
       - name: Upload Anchore Scan Report
-        uses: github/codeql-action/upload-sarif@v2
+        uses: github/codeql-action/upload-sarif@82a3f64131759f97922e0680c3730858bc7155a6 # v2
         if: always()
         with:
           sarif_file: results.sarif
diff --git a/.github/workflows/check_pr.yml b/.github/workflows/check_pr.yml
index cce975c..bb83a15 100644
--- a/.github/workflows/check_pr.yml
+++ b/.github/workflows/check_pr.yml
@@ -24,7 +24,7 @@ jobs:
     steps:
       - name: Assign Me
         # You may pin to the exact commit or the version.
-        uses: kentaro-m/auto-assign-action@v1.2.1
+        uses: kentaro-m/auto-assign-action@746a3a558fdd0e061f612ec9f8ff1b8a19c1a115 # v1.2.1
         with:
           configuration-path: '.github/auto_assign.yml'
 
@@ -33,7 +33,7 @@ jobs:
     runs-on: ubuntu-latest
     steps:
       - name: Checkout
-        uses: actions/checkout@v3
+        uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # v3
 
       - name: Formatting
         id: format
@@ -43,7 +43,7 @@ jobs:
           path: .
           fail-on-changes: false
 
-      - uses: actions/github-script@v6.3.3
+      - uses: actions/github-script@d556feaca394842dc55e4734bf3bb9f685482fa0 # v6.3.3
         if: steps.format.outcome != 'success'
         with:
           github-token: ${{ secrets.GITHUB_TOKEN }}
@@ -77,12 +77,12 @@ jobs:
     runs-on: ubuntu-latest
     name: Check Size
     steps:
-      - uses: actions/checkout@v3
+      - uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # v3
         with:
           fetch-depth: 0
 
       - name: Check Size
-        uses: actions/github-script@v6.3.3
+        uses: actions/github-script@d556feaca394842dc55e4734bf3bb9f685482fa0 # v6.3.3
         env:
           IGNORED_FILES: openapi.json, openapi-node.json
         with:
diff --git a/.github/workflows/code_review.yml b/.github/workflows/code_review.yml
index 931e0ee..27fa95e 100644
--- a/.github/workflows/code_review.yml
+++ b/.github/workflows/code_review.yml
@@ -34,12 +34,12 @@ jobs:
 
     # Steps represent a sequence of tasks that will be executed as part of the job
     steps:
-      - uses: actions/checkout@v3
+      - uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # v3
         with:
           fetch-depth: 0
 
       - name: Set Node.js 16
-        uses: actions/setup-node@v3
+        uses: actions/setup-node@1a4442cacd436585916779262731d5b162bc6ec7 # v3
         with:
           node-version: 14.19.0
 
diff --git a/.github/workflows/create_dashboard.yaml b/.github/workflows/create_dashboard.yaml
index 90b09ea..d78bd85 100644
--- a/.github/workflows/create_dashboard.yaml
+++ b/.github/workflows/create_dashboard.yaml
@@ -39,7 +39,7 @@ jobs:
           persist-credentials: false
 
       # from https://github.com/pagopa/opex-dashboard-azure-action/
-      - uses: pagopa/opex-dashboard-azure-action@v1.1.2
+      - uses: pagopa/opex-dashboard-azure-action@ece3bc2b133be74cabb50aec14cdb9b8051b886f # v1.1.2
         with:
           environment: ${{ matrix.environment }}
           api-name: ${{ matrix.product }}
@@ -56,7 +56,7 @@ jobs:
     if: ${{ always() }}
     steps:
       - name: Delete Previous deployments
-        uses: actions/github-script@v6
+        uses: actions/github-script@d7906e4ad0b1822421a7e6a35d5ca353c962f410 # v6
         env:
           SHA_HEAD: ${{ (github.event_name == 'pull_request' && github.event.pull_request.head.sha) || github.sha}}
         with:
diff --git a/.github/workflows/integration_test.yml b/.github/workflows/integration_test.yml
index c405e3e..002e641 100644
--- a/.github/workflows/integration_test.yml
+++ b/.github/workflows/integration_test.yml
@@ -70,7 +70,7 @@ jobs:
     steps:
       - name: Report Status
         if: ${{ inputs.notify }}
-        uses: ravsamhq/notify-slack-action@v2
+        uses: ravsamhq/notify-slack-action@be814b201e233b2dc673608aa46e5447c8ab13f2 # v2
         with:
           status: ${{ needs.integration_test.result }}
           token: ${{ secrets.GITHUB_TOKEN }}
@@ -87,7 +87,7 @@ jobs:
     if: ${{ always() }}
     steps:
       - name: Delete Previous deployments
-        uses: actions/github-script@v6
+        uses: actions/github-script@d7906e4ad0b1822421a7e6a35d5ca353c962f410 # v6
         env:
           SHA_HEAD: ${{ (github.event_name == 'pull_request' && github.event.pull_request.head.sha) || github.sha}}
         with:
diff --git a/.github/workflows/release_deploy.yml b/.github/workflows/release_deploy.yml
index 0bc1072..be21065 100644
--- a/.github/workflows/release_deploy.yml
+++ b/.github/workflows/release_deploy.yml
@@ -112,7 +112,7 @@ jobs:
     steps:
       - name: Build and Push
         id: semver
-        uses: pagopa/github-actions-template/ghcr-build-push@v1.5.4
+        uses: pagopa/github-actions-template/ghcr-build-push@d91a1fd0b913c9830589be5d86cdb71c90813fae # v1.5.4
         with:
           branch: ${{ github.ref_name}}
           github_token: ${{ secrets.GITHUB_TOKEN }}
@@ -139,7 +139,7 @@ jobs:
     steps:
       - name: Report Status
         if: ${{ needs.setup.outputs.environment == 'prod' || needs.setup.outputs.environment == 'all'  }}
-        uses: ravsamhq/notify-slack-action@v2
+        uses: ravsamhq/notify-slack-action@be814b201e233b2dc673608aa46e5447c8ab13f2 # v2
         with:
           status: ${{ needs.deploy_aks.result }}
           token: ${{ secrets.GITHUB_TOKEN }}
diff --git a/.github/workflows/update_code.yml b/.github/workflows/update_code.yml
index ed41d83..8b42a43 100644
--- a/.github/workflows/update_code.yml
+++ b/.github/workflows/update_code.yml
@@ -17,7 +17,7 @@ jobs:
     if: ${{ contains(github.event.comment.body, 'update_code') }}
     steps:
       - name: Checkout
-        uses: actions/checkout@v3
+        uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # v3
         with:
           token: ${{ secrets.BOT_TOKEN_GITHUB }}
 
@@ -26,7 +26,7 @@ jobs:
         env:
           GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
       - name: Set up JDK 11
-        uses: actions/setup-java@v1
+        uses: actions/setup-java@b6e674f4b717d7b0ae3baee0fbe79f498905dfde # v1
         with:
           java-version: 11
 
@@ -58,7 +58,7 @@ jobs:
     if: ${{ always() && contains(needs.*.result, 'failure') }}
     steps:
       - name: Notify if Failure
-        uses: actions/github-script@v6.3.3
+        uses: actions/github-script@d556feaca394842dc55e4734bf3bb9f685482fa0 # v6.3.3
         with:
           github-token: ${{ secrets.GITHUB_TOKEN }}
           script: |
diff --git a/.github/workflows/update_infra.yml b/.github/workflows/update_infra.yml
index cd4d294..78fa273 100644
--- a/.github/workflows/update_infra.yml
+++ b/.github/workflows/update_infra.yml
@@ -15,7 +15,7 @@ jobs:
     runs-on: ubuntu-latest
     steps:
       - name: Checkout
-        uses: actions/checkout@v2
+        uses: actions/checkout@ee0669bd1cc54295c223e0bb666b733df41de1c5 # v2
 
       # prepare openapi template for infra repo
       - run: |
diff --git a/Dockerfile b/Dockerfile
index 23a371e..c8e4d3b 100644
--- a/Dockerfile
+++ b/Dockerfile
@@ -1,4 +1,4 @@
-FROM node:14.19.0
+FROM node:14.19.0@sha256:224cb9e0a988e1f6cc9b2c30be4dc508ef0ee1199b0f507d27297ff026d742c8
 
 WORKDIR /src/node-function-app