From de59cf40134809f5c7faff7e06331fc0663c274f Mon Sep 17 00:00:00 2001 From: Carmen Date: Tue, 15 Sep 2026 13:43:45 +0200 Subject: [PATCH] use sha pinning;fix softprops/action-gh-release inputs --- .github/workflows/codeql.yml | 6 +++--- .github/workflows/grass-manual.yml | 6 +++--- .github/workflows/grass-tests.yml | 6 +++--- .github/workflows/lint-workflows.yaml | 6 +++--- .github/workflows/linting.yml | 12 ++++++------ .github/workflows/post-pr-reviews.yml | 4 ++-- .github/workflows/python-publish.yml | 8 ++++---- .github/workflows/sbom-vulnerability-scan.yml | 16 ++++++++-------- .github/workflows/third-party-licenses.yml | 17 +++++++---------- 9 files changed, 39 insertions(+), 42 deletions(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index f5a7170..f98afca 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -46,7 +46,7 @@ jobs: # your codebase is analyzed, see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages steps: - name: Checkout repository - uses: actions/checkout@v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Check whether language exists id: check-language @@ -79,7 +79,7 @@ jobs: # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL if: steps.check-language.outputs.exists == 'true' - uses: github/codeql-action/init@v4 + uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 with: languages: ${{ matrix.language }} build-mode: ${{ matrix.build-mode }} @@ -109,6 +109,6 @@ jobs: - name: Perform CodeQL Analysis if: steps.check-language.outputs.exists == 'true' - uses: github/codeql-action/analyze@v4 + uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 with: category: "/language:${{matrix.language}}" diff --git a/.github/workflows/grass-manual.yml b/.github/workflows/grass-manual.yml index 8eddf22..0fb783a 100644 --- a/.github/workflows/grass-manual.yml +++ b/.github/workflows/grass-manual.yml @@ -10,7 +10,7 @@ jobs: name: build-grass-manual runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Creation of GRASS GIS addon manual run: | ADDON_NAME=$(echo ${GITHUB_REPOSITORY} | cut -d "/" -f 2) @@ -20,7 +20,7 @@ jobs: echo $ID docker cp $ID:/src/build/docs/html public - name: Upload Pages artifact - uses: actions/upload-pages-artifact@v5 + uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0 with: path: "public" @@ -41,4 +41,4 @@ jobs: steps: - name: Deploy to GitHub Pages id: deployment - uses: actions/deploy-pages@v5 + uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 # v5.0.1 diff --git a/.github/workflows/grass-tests.yml b/.github/workflows/grass-tests.yml index 7228db7..e0028d4 100644 --- a/.github/workflows/grass-tests.yml +++ b/.github/workflows/grass-tests.yml @@ -16,9 +16,9 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v4 + uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0 - name: add Dockerfile and test skript run: | ( mkdir -p test-docker && cd test-docker && \ @@ -26,7 +26,7 @@ jobs: && wget https://raw.githubusercontent.com/mundialis/github-workflows/main/grass-gis-test-docker/test.sh ) - name: Tests of GRASS GIS addon id: docker_build - uses: docker/build-push-action@v7 + uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 with: push: false tags: addon-tests:alpine diff --git a/.github/workflows/lint-workflows.yaml b/.github/workflows/lint-workflows.yaml index 8d1d2b3..e75d8f6 100644 --- a/.github/workflows/lint-workflows.yaml +++ b/.github/workflows/lint-workflows.yaml @@ -11,7 +11,7 @@ jobs: lint: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7 - - uses: cschleiden/actions-linter@v1 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: raven-actions/actionlint@3d39aea434753780c3b3d4a1a31c854b4dbf49d7 # v2.2.0 with: - workflows: '[".github/workflows/*.yaml"]' + files: ".github/workflows/*.yaml" diff --git a/.github/workflows/linting.yml b/.github/workflows/linting.yml index a7bc05a..e484886 100644 --- a/.github/workflows/linting.yml +++ b/.github/workflows/linting.yml @@ -91,7 +91,7 @@ jobs: if: ${{ inputs.flake8-version != '' }} runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Install apt dependencies run: | sudo apt-get install -y -qq python3 python3-pip @@ -108,7 +108,7 @@ jobs: if: ${{ inputs.pylint-version != '' }} runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Install apt dependencies run: | sudo apt-get install -y -qq python3 python3-pip @@ -138,7 +138,7 @@ jobs: if: ${{ inputs.black-version != '' }} runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Install apt dependencies run: | sudo apt-get install -y -qq python3 python3-pip @@ -161,7 +161,7 @@ jobs: if: ${{ inputs.ruff-version != '' }} runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Install apt dependencies run: | sudo apt-get install -y -qq python3 python3-pip @@ -205,13 +205,13 @@ jobs: # To report GitHub Actions status checks statuses: write steps: - - uses: actions/checkout@v7 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: # super-linter needs the full git history to get the # list of files that changed across commits fetch-depth: 0 - name: Lint code base - uses: super-linter/super-linter/slim@v8 + uses: super-linter/super-linter/slim@4ce20838b8ab83717e78138c5b3a1407148e0918 # v8.7.0 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} DEFAULT_BRANCH: main diff --git a/.github/workflows/post-pr-reviews.yml b/.github/workflows/post-pr-reviews.yml index aa7e445..41fb11e 100644 --- a/.github/workflows/post-pr-reviews.yml +++ b/.github/workflows/post-pr-reviews.yml @@ -20,14 +20,14 @@ jobs: steps: - name: Create a .git directory needed by reviewdog run: git init - - uses: actions/download-artifact@v8 + - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 id: diff continue-on-error: true with: name: diff github-token: ${{ github.token }} run-id: ${{github.event.workflow_run.id }} - - uses: reviewdog/action-setup@v1 + - uses: reviewdog/action-setup@d8a7baabd7f3e8544ee4dbde3ee41d0011c3a93f # v1.5.0 - name: Check what tools have suggestions to post # Using this pattern to have expected file names explicitly named id: tools diff --git a/.github/workflows/python-publish.yml b/.github/workflows/python-publish.yml index 3dbfbf0..56772b0 100644 --- a/.github/workflows/python-publish.yml +++ b/.github/workflows/python-publish.yml @@ -18,7 +18,7 @@ jobs: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Install dependencies run: | # noninteractive is necessary to install libgdal-dev @@ -38,12 +38,12 @@ jobs: - name: Build package run: python3 -m build --outdir build . - name: Release - uses: softprops/action-gh-release@v3 + uses: softprops/action-gh-release@3d0d9888cb7fd7b750713d6e236d1fcb99157228 # v3.0.2 if: startsWith(github.ref, 'refs/tags/') with: files: build/*.whl - name: Publish package to test pypi - uses: pypa/gh-action-pypi-publish@release/v1 + uses: pypa/gh-action-pypi-publish@release/dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1.14.2 if: ${{ inputs.test_pypi }} with: repository_url: https://test.pypi.org/legacy/ @@ -51,7 +51,7 @@ jobs: packages_dir: build/ verbose: true - name: Publish package to pypi - uses: pypa/gh-action-pypi-publish@release/v1 + uses: pypa/gh-action-pypi-publish@release/dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1.14.2 if: ${{ inputs.test_pypi == false }} with: password: ${{ secrets.PYPI_PASSWORD }} diff --git a/.github/workflows/sbom-vulnerability-scan.yml b/.github/workflows/sbom-vulnerability-scan.yml index 44fcec8..2001a9f 100644 --- a/.github/workflows/sbom-vulnerability-scan.yml +++ b/.github/workflows/sbom-vulnerability-scan.yml @@ -55,7 +55,7 @@ jobs: fi - name: Checkout the code - uses: actions/checkout@v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: ${{ inputs.fetch_depth }} @@ -66,7 +66,7 @@ jobs: - name: Generate SBOM from Docker image if: inputs.dockerfile != '' - uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0 + uses: anchore/sbom-action@3ad7283483fc7af8ff2b4ea19663c2d5ca935e26 # v0.24.2 with: image: localbuild/testimage:latest artifact-name: docker.cyclonedx.json @@ -76,16 +76,16 @@ jobs: - name: Scan Docker SBOM for vulnerabilities if: inputs.dockerfile != '' id: docker-vulnerability-scan - uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 + uses: anchore/scan-action@27805bf3b4e84b4a5c980df22ed233c00390a439 # v7.4.2 with: - image: + image: sbom: docker.cyclonedx.json fail-build: ${{ inputs.fail-build }} output-format: sarif - name: Upload Docker vulnerability results to GitHub Security if: inputs.dockerfile != '' - uses: github/codeql-action/upload-sarif@v4 + uses: github/codeql-action/upload-sarif@24ea975727876cf496b1eb0c5b36e96e01600b51 # v4.37.0 with: sarif_file: ${{ steps.docker-vulnerability-scan.outputs.sarif }} category: grype-docker @@ -124,7 +124,7 @@ jobs: - name: Generate SBOM from Python environment if: inputs.requirements != '' || inputs.pyproject != '' - uses: anchore/sbom-action@v0.24.2 + uses: anchore/sbom-action@3ad7283483fc7af8ff2b4ea19663c2d5ca935e26 # v0.24.2 with: path: .sbom_venv artifact-name: python.cyclonedx.json @@ -134,7 +134,7 @@ jobs: - name: Scan Python environment for vulnerabilities if: inputs.requirements != '' || inputs.pyproject != '' id: python-vulnerability-scan - uses: anchore/scan-action@v7 + uses: anchore/scan-action@27805bf3b4e84b4a5c980df22ed233c00390a439 # v7.4.2 with: # Scan the .sbom_venv directly instead of the generated SBOM because # the SBOM scan produced empty SARIF artifact locations, while @@ -145,7 +145,7 @@ jobs: - name: Upload Python vulnerability results to GitHub Security if: inputs.requirements != '' || inputs.pyproject != '' - uses: github/codeql-action/upload-sarif@v4 + uses: github/codeql-action/upload-sarif@24ea975727876cf496b1eb0c5b36e96e01600b51 # v4.37.0 with: sarif_file: ${{ steps.python-vulnerability-scan.outputs.sarif }} category: grype-python diff --git a/.github/workflows/third-party-licenses.yml b/.github/workflows/third-party-licenses.yml index 28b1863..dfd2fe9 100644 --- a/.github/workflows/third-party-licenses.yml +++ b/.github/workflows/third-party-licenses.yml @@ -27,7 +27,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Validate inputs id: validate @@ -124,7 +124,7 @@ jobs: " - name: Generate SBOM from Docker image if: inputs.dockerfile != '' - uses: anchore/sbom-action@v0.24.2 + uses: anchore/sbom-action@3ad7283483fc7af8ff2b4ea19663c2d5ca935e26 # v0.24.2 with: image: license-scan-image format: syft-json @@ -151,30 +151,27 @@ jobs: python3 -c "import json; json.load(open('THIRD_PARTY_LICENSES.json'))" - name: Upload THIRD_PARTY_LICENSES.json as artifact - uses: actions/upload-artifact@v7 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: third-party-license path: THIRD_PARTY_LICENSES.json - name: Upload as release asset - uses: softprops/action-gh-release@v3 + uses: softprops/action-gh-release@3d0d9888cb7fd7b750713d6e236d1fcb99157228 # v3.0.2 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} with: - upload_url: ${{ github.event.release.upload_url }} - asset_path: ./THIRD_PARTY_LICENSES.json - asset_name: THIRD_PARTY_LICENSES.json - asset_content_type: application/json + files: ./THIRD_PARTY_LICENSES.json license-scan: runs-on: ubuntu-latest needs: generate continue-on-error: true steps: - - uses: actions/checkout@v7 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Download THIRD_PARTY_LICENSES.json - uses: actions/download-artifact@v8 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: third-party-license path: .