diff --git a/.github/workflows/automerge.yml b/.github/workflows/automerge.yml index c4165ba31..c1293cb00 100644 --- a/.github/workflows/automerge.yml +++ b/.github/workflows/automerge.yml @@ -23,7 +23,7 @@ jobs: runs-on: ubuntu-latest steps: - name: automerge - uses: pascalgn/automerge-action@v0.12.0 + uses: pascalgn/automerge-action@c9bd1823770819dc8fb8a5db2d11a3a95fbe9b07 # v0.12.0 env: # Allows this merge to trigger other actions GITHUB_TOKEN: "${{ secrets.GITHUB_TOKEN }}" diff --git a/.github/workflows/pr-auditor.yml b/.github/workflows/pr-auditor.yml index 3fe422331..7a485398c 100644 --- a/.github/workflows/pr-auditor.yml +++ b/.github/workflows/pr-auditor.yml @@ -8,9 +8,9 @@ jobs: check-pr: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v2 + - uses: actions/checkout@dc323e67f16fb5f7663d20ff7941f27f5809e9b6 # v2 with: { repository: 'sourcegraph/sourcegraph' } - - uses: actions/setup-go@v2 + - uses: actions/setup-go@bfdd3570ce990073878bf10f6b2d79082de49492 # v2 with: { go-version: '1.18' } - run: ./dev/pr-auditor/check-pr.sh diff --git a/.github/workflows/update-tags.yml b/.github/workflows/update-tags.yml index 96dd66ad4..0368dcaf6 100644 --- a/.github/workflows/update-tags.yml +++ b/.github/workflows/update-tags.yml @@ -11,8 +11,8 @@ jobs: dispatch: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v2 - - uses: actions/setup-go@v2 + - uses: actions/checkout@dc323e67f16fb5f7663d20ff7941f27f5809e9b6 # v2 + - uses: actions/setup-go@bfdd3570ce990073878bf10f6b2d79082de49492 # v2 with: go-version: "^1.19" @@ -20,7 +20,7 @@ jobs: - name: Pin tags to ${{ github.event.inputs.semver }} run: tools/update-docker-tags.sh "${{ github.event.inputs.semver }}" - name: Open pull request - uses: peter-evans/create-pull-request@v3 + uses: peter-evans/create-pull-request@18f7dc018cc2cd597073088f7c7591b9d1c02672 # v3 with: token: ${{ secrets.GITHUB_TOKEN }} base: ${{ github.event.inputs.branch }}