Skip to content

Commit e4fb59e

Browse files
Pin dependencies
1 parent 39d670d commit e4fb59e

File tree

8 files changed

+20
-20
lines changed

8 files changed

+20
-20
lines changed

.github/workflows/publish-release-npm-package.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,10 +17,10 @@ jobs:
1717
id-token: write
1818
steps:
1919
- name: 🧮 Checkout code
20-
uses: actions/checkout@v4
20+
uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4
2121

2222
- name: 🔧 Yarn cache
23-
uses: actions/setup-node@v4
23+
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
2424
with:
2525
cache: "yarn"
2626
registry-url: "https://registry.npmjs.org"

.github/workflows/reusable-playwright-tests.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -14,11 +14,11 @@ jobs:
1414
name: Run Playwright end-to-end tests & upload html report
1515
runs-on: ubuntu-24.04-arm
1616
steps:
17-
- uses: actions/checkout@v4
17+
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4
1818
with:
1919
repository: ${{ inputs.webapp-artifact && 'element-hq/element-modules' || github.repository }}
2020

21-
- uses: actions/setup-node@v4
21+
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
2222
with:
2323
cache: "yarn"
2424
node-version: "lts/*"
@@ -31,7 +31,7 @@ jobs:
3131
run: echo "version=$(yarn list --pattern @playwright/test --depth=0 --json --non-interactive --no-progress | jq -r '.data.trees[].name')" >> "$GITHUB_OUTPUT"
3232

3333
- name: Cache playwright binaries
34-
uses: actions/cache@v4
34+
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4
3535
id: playwright-cache
3636
with:
3737
path: ~/.cache/ms-playwright
@@ -43,7 +43,7 @@ jobs:
4343

4444
- name: Fetch webapp
4545
if: inputs.webapp-artifact
46-
uses: actions/download-artifact@v4
46+
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
4747
with:
4848
name: ${{ inputs.webapp-artifact }}
4949
path: webapp
@@ -60,7 +60,7 @@ jobs:
6060

6161
- name: Upload blob report to GitHub Actions Artifacts
6262
if: always()
63-
uses: actions/upload-artifact@v4
63+
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
6464
with:
6565
name: playwright-html-report
6666
path: playwright-report

.github/workflows/sonarqube.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,7 @@ jobs:
3838
fetch-depth: 0 # Shallow clones should be disabled for a better relevancy of analysis
3939

4040
- name: 📥 Download artifact
41-
uses: actions/download-artifact@v4
41+
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
4242
with:
4343
github-token: ${{ secrets.GITHUB_TOKEN }}
4444
run-id: ${{ github.event.workflow_run.id }}
@@ -56,7 +56,7 @@ jobs:
5656
5757
- name: "🩻 SonarCloud Scan"
5858
id: sonarcloud
59-
uses: matrix-org/[email protected]
59+
uses: matrix-org/sonarcloud-workflow-action@6fa326fe328568a4800c431fe864826caff79b41 # v3.3
6060
# workflow_run fails report against the develop commit always, we don't want that for PRs
6161
continue-on-error: ${{ github.event.workflow_run.head_branch != 'develop' }}
6262
with:

.github/workflows/static-analysis.yaml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -24,14 +24,14 @@ jobs:
2424
- lint:prettier
2525
- lint:knip
2626
steps:
27-
- uses: actions/checkout@v4
27+
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4
2828

29-
- uses: actions/setup-node@v4
29+
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
3030
with:
3131
cache: "yarn"
3232
node-version: "lts/*"
3333

34-
- uses: actions/setup-python@v5
34+
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5
3535
with:
3636
python-version: "3.11"
3737

.github/workflows/synapse-module.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ jobs:
1717
env:
1818
DOCKER_IMAGE: ghcr.io/element-hq/synapse-guest-module
1919
steps:
20-
- uses: actions/checkout@v4
20+
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4
2121

2222
- name: Login to ghcr.io
2323
uses: docker/login-action@v3

.github/workflows/tests.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -14,14 +14,14 @@ jobs:
1414
name: Run tests & upload coverage reports
1515
runs-on: ubuntu-24.04-arm
1616
steps:
17-
- uses: actions/checkout@v4
17+
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4
1818

19-
- uses: actions/setup-node@v4
19+
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
2020
with:
2121
cache: "yarn"
2222
node-version: "lts/*"
2323

24-
- uses: actions/setup-python@v5
24+
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5
2525
with:
2626
python-version: "3.11"
2727

@@ -35,7 +35,7 @@ jobs:
3535
run: sed -ie 's/filename="/filename="modules\/restricted-guests\/synapse\//' modules/restricted-guests/synapse/coverage.xml
3636

3737
- name: Upload Artifact
38-
uses: actions/upload-artifact@v4
38+
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
3939
with:
4040
name: coverage
4141
path: |

modules/restricted-guests/synapse/Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
ARG DEBIAN_VERSION_NUMERIC=12
22

33
# Now copy it into our base image.
4-
FROM gcr.io/distroless/base-nossl-debian${DEBIAN_VERSION_NUMERIC}:debug AS build
4+
FROM gcr.io/distroless/base-nossl-debian${DEBIAN_VERSION_NUMERIC}:debug@sha256:1a14fd3ffe3745e5523faa1740904dfd851c324957e230ea2db31601e2f537ec AS build
55

66
FROM gcr.io/distroless/base-nossl-debian${DEBIAN_VERSION_NUMERIC}
77

packages/element-web-module-api/Dockerfile

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
1-
ARG ELEMENT_VERSION=latest
1+
ARG ELEMENT_VERSION=latest@sha256:6e91e641abe70dd02f1461b4f1ebf8f6807bfa381ec7f2c13e9e286c4e2b2918
22

3-
FROM --platform=$BUILDPLATFORM node:lts-alpine AS builder
3+
FROM --platform=$BUILDPLATFORM node:lts-alpine@sha256:dbcedd8aeab47fbc0f4dd4bffa55b7c3c729a707875968d467aaaea42d6225af AS builder
44

55
ARG BUILD_CONTEXT
66

0 commit comments

Comments
 (0)