diff --git a/.github/workflows/autofix.yml b/.github/workflows/autofix.yml index c9fbcc4..dd92bd2 100644 --- a/.github/workflows/autofix.yml +++ b/.github/workflows/autofix.yml @@ -15,4 +15,4 @@ permissions: jobs: dependabot-bun-dedupe: - uses: stella/.github/.github/workflows/dependabot-bun-dedupe.yml@dd6e8fa51339814159486cd92b5ae3a051eb15d2 + uses: stella/.github/.github/workflows/dependabot-bun-dedupe.yml@fb1e83fbc3fae39902da763ca7b2613090571717 diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 1504dde..77b3dff 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -217,7 +217,7 @@ jobs: # snapshot-hygiene gate, `cargo ci-snapshot`); avoids a from-source # compile on every CI run. taiki-e/install-action verifies release # checksums, unlike a raw `curl | tar`. - uses: taiki-e/install-action@b6b84cf49ebfe0176417bdce007c624f0db37f20 # v2.86.2 + uses: taiki-e/install-action@d438492cf8a250514fa2d34b30bc3c0dc37c65ff # v2.87.8 with: tool: nextest@0.9.140,cargo-deny@0.20.2,cargo-insta@1.48.0 diff --git a/.github/workflows/cla.yml b/.github/workflows/cla.yml index 1daa833..53fe299 100644 --- a/.github/workflows/cla.yml +++ b/.github/workflows/cla.yml @@ -27,7 +27,7 @@ jobs: || github.event.comment.body == 'I have read the CLA Document and I hereby sign the CLA' ) ) - uses: stella/.github/.github/workflows/cla.yml@48aacae31829ce15216a6b766b03a92fd2e84da3 + uses: stella/.github/.github/workflows/cla.yml@fb1e83fbc3fae39902da763ca7b2613090571717 with: allowlist: dependabot[bot],renovate[bot],github-actions[bot],google-labs-jules[bot],cursoragent secrets: diff --git a/.github/workflows/mutants.yml b/.github/workflows/mutants.yml index 8b9ec1b..7af4712 100644 --- a/.github/workflows/mutants.yml +++ b/.github/workflows/mutants.yml @@ -34,7 +34,7 @@ jobs: - name: Install pinned Rust tools (checksum-verified) # nextest is the test runner used by cargo-mutants. taiki-e/install-action # verifies release checksums, unlike a raw `curl | tar`. - uses: taiki-e/install-action@b6b84cf49ebfe0176417bdce007c624f0db37f20 # v2.86.2 + uses: taiki-e/install-action@d438492cf8a250514fa2d34b30bc3c0dc37c65ff # v2.87.8 with: tool: nextest@0.9.140,cargo-mutants@27.1.0 diff --git a/.github/workflows/quarantine-policy.yml b/.github/workflows/quarantine-policy.yml index bbac3ff..c1076d4 100644 --- a/.github/workflows/quarantine-policy.yml +++ b/.github/workflows/quarantine-policy.yml @@ -13,4 +13,4 @@ jobs: if: github.repository == 'stella/stdnum' permissions: contents: read - uses: stella/.github/.github/workflows/quarantine-policy.yml@9e1915536efc226c5ec9d3ca0f2192be5aa6ec7e + uses: stella/.github/.github/workflows/quarantine-policy.yml@fb1e83fbc3fae39902da763ca7b2613090571717 diff --git a/.github/workflows/quarantine-prune.yml b/.github/workflows/quarantine-prune.yml index 711b70c..a9a9990 100644 --- a/.github/workflows/quarantine-prune.yml +++ b/.github/workflows/quarantine-prune.yml @@ -13,7 +13,7 @@ jobs: if: github.repository == 'stella/stdnum' permissions: contents: read - uses: stella/.github/.github/workflows/quarantine-prune.yml@9e1915536efc226c5ec9d3ca0f2192be5aa6ec7e + uses: stella/.github/.github/workflows/quarantine-prune.yml@fb1e83fbc3fae39902da763ca7b2613090571717 secrets: CHANGELOG_APP_ID: ${{ secrets.CHANGELOG_APP_ID }} CHANGELOG_APP_PRIVATE_KEY: ${{ secrets.CHANGELOG_APP_PRIVATE_KEY }} diff --git a/.github/workflows/release-policy.yml b/.github/workflows/release-policy.yml index d8ced8f..2615b53 100644 --- a/.github/workflows/release-policy.yml +++ b/.github/workflows/release-policy.yml @@ -18,6 +18,6 @@ permissions: jobs: enforce: name: Enforce release boundaries - uses: stella/.github/.github/workflows/release-policy.yml@0f814e1a0c6c7401778e661209553b6e15f8d92a + uses: stella/.github/.github/workflows/release-policy.yml@fb1e83fbc3fae39902da763ca7b2613090571717 permissions: contents: read diff --git a/.github/workflows/release-pr.yml b/.github/workflows/release-pr.yml index 14b64a4..fe25c06 100644 --- a/.github/workflows/release-pr.yml +++ b/.github/workflows/release-pr.yml @@ -15,7 +15,7 @@ jobs: name: Maintain version packages PR permissions: contents: read - uses: stella/.github/.github/workflows/changeset-release-pr.yml@c56b0c1d1e82f5e3fffa733a32b9a503a172ee35 + uses: stella/.github/.github/workflows/changeset-release-pr.yml@fb1e83fbc3fae39902da763ca7b2613090571717 with: bun-version-file: package.json sync-cargo-inherited-lock: true diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index add6aeb..64b6af8 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -331,7 +331,7 @@ jobs: id-token: write # Required only for PyPI trusted publishing. steps: - name: Prepare exact Python wheel set - uses: stella/.github/.github/actions/pypi-publish-hardened@0f814e1a0c6c7401778e661209553b6e15f8d92a + uses: stella/.github/.github/actions/pypi-publish-hardened@fb1e83fbc3fae39902da763ca7b2613090571717 with: expected-version: ${{ needs.verify.outputs.version }} project-name: stella-stdnum @@ -344,7 +344,7 @@ jobs: packages-dir: dist skip-existing: true - name: Verify published PyPI files - uses: stella/.github/.github/actions/pypi-publish-hardened/verify@0f814e1a0c6c7401778e661209553b6e15f8d92a + uses: stella/.github/.github/actions/pypi-publish-hardened/verify@fb1e83fbc3fae39902da763ca7b2613090571717 with: expected-version: ${{ needs.verify.outputs.version }} project-name: stella-stdnum @@ -354,7 +354,7 @@ jobs: needs: [verify, pack-native, pack-portable, publish-pypi] if: github.ref == 'refs/heads/main' && (needs.verify.outputs.publish == 'true') - uses: stella/.github/.github/workflows/npm-version-finalize.yml@0f814e1a0c6c7401778e661209553b6e15f8d92a + uses: stella/.github/.github/workflows/npm-version-finalize.yml@fb1e83fbc3fae39902da763ca7b2613090571717 with: package-files: | packages/stdnum/package.json diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index e0dde25..6feab60 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -30,6 +30,6 @@ jobs: publish_results: true - name: Upload SARIF to GitHub Security tab - uses: github/codeql-action/upload-sarif@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd # v4.37.7 + uses: github/codeql-action/upload-sarif@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 with: sarif_file: results.sarif