diff --git a/.github/workflows/book.yml b/.github/workflows/book.yml index 778b80a..594531b 100644 --- a/.github/workflows/book.yml +++ b/.github/workflows/book.yml @@ -45,18 +45,21 @@ jobs: name: build runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 - - uses: astral-sh/setup-uv@v5 + - uses: astral-sh/setup-uv@d4b2f3b6ecc6e67c4457f6d3e41ec42d3d0fcb86 # v5.4.2 with: enable-cache: true + # uv itself, the same one ci.yml pins, so the build does not move + # with each uv release. + version: "0.11.28" # Pinned, because an unpinned theme turns an unrelated upstream release # into a red build on a PR that only touched the collector. - name: Build run: uvx --with mkdocs-material==9.6.14 mkdocs build --strict - - uses: actions/upload-pages-artifact@v3 + - uses: actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa # v3.0.1 with: path: _book @@ -76,4 +79,4 @@ jobs: id-token: write steps: - id: deployment - uses: actions/deploy-pages@v4 + uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e # v4.0.5 diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index c46b756..f6b222c 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -40,9 +40,9 @@ jobs: run: working-directory: collector steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 - - uses: astral-sh/setup-uv@v5 + - uses: astral-sh/setup-uv@d4b2f3b6ecc6e67c4457f6d3e41ec42d3d0fcb86 # v5.4.2 with: enable-cache: true # uv itself, so the resolver reading the lock is the same every run. @@ -77,7 +77,7 @@ jobs: # this is a `uses` step - getting that wrong uploads an empty artifact and # the column silently reads "no report". - name: Upload coverage report - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 with: name: coverage-report path: collector/_tests/coverage.xml @@ -94,9 +94,9 @@ jobs: run: working-directory: collector steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 - - uses: astral-sh/setup-uv@v5 + - uses: astral-sh/setup-uv@d4b2f3b6ecc6e67c4457f6d3e41ec42d3d0fcb86 # v5.4.2 with: enable-cache: true # uv itself, so the resolver reading the lock is the same every run. @@ -109,7 +109,7 @@ jobs: name: dashboards runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 - name: Panel ids, link targets and grid overlaps run: python3 scripts/check-dashboard.py @@ -118,7 +118,7 @@ jobs: name: image builds and comes up runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 - name: Build run: docker build -t jq-monitoring:ci . diff --git a/.github/workflows/image.yml b/.github/workflows/image.yml index b01f4d5..3c4e019 100644 --- a/.github/workflows/image.yml +++ b/.github/workflows/image.yml @@ -29,21 +29,21 @@ jobs: publish: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 # Apple silicon and CI runners are not the same architecture, and the # README is written for a laptop. Both or the recipe does not work. - - uses: docker/setup-qemu-action@v3 - - uses: docker/setup-buildx-action@v3 + - uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130 # v3.7.0 + - uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0 - - uses: docker/login-action@v3 + - uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3.7.0 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - id: meta - uses: docker/metadata-action@v5 + uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5.10.0 # ghcr.io reads a multi-arch package's description off the manifest # index, not off the per-platform image configs where --label lands, so # the labels alone leave the package page blank. Ask for index-level @@ -57,7 +57,7 @@ jobs: type=semver,pattern={{version}} type=sha,format=short - - uses: docker/build-push-action@v6 + - uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6.19.2 with: context: . platforms: linux/amd64,linux/arm64