Skip to content

Commit a113a52

Browse files
authored
chore: pin third-party GitHub Actions to commit SHAs (#45)
1 parent 22ccdce commit a113a52

File tree

2 files changed

+3
-3
lines changed

2 files changed

+3
-3
lines changed

.github/workflows/manual-publish.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@ jobs:
3535

3636
- name: Publish package distributions to PyPI
3737
if: ${{ format('{0}', inputs.dry_run) == 'false' }}
38-
uses: pypa/gh-action-pypi-publish@release/v1
38+
uses: pypa/gh-action-pypi-publish@ed0c53931b1dc9bd32cbe73a98c7f6766f8a527e # v1.13.0
3939
with:
4040
password: ${{env.PYPI_AUTH_TOKEN}}
4141

.github/workflows/release-please.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ jobs:
1313
pull-requests: write
1414
attestations: write
1515
steps:
16-
- uses: googleapis/release-please-action@v4
16+
- uses: googleapis/release-please-action@16a9c90856f42705d54a6fda1823352bdc62cf38 # v4.4.0
1717
id: release
1818

1919
- uses: actions/checkout@v4
@@ -45,7 +45,7 @@ jobs:
4545

4646
- name: Publish package distributions to PyPI
4747
if: ${{ steps.release.outputs.releases_created == 'true' }}
48-
uses: pypa/gh-action-pypi-publish@release/v1
48+
uses: pypa/gh-action-pypi-publish@ed0c53931b1dc9bd32cbe73a98c7f6766f8a527e # v1.13.0
4949
with:
5050
password: ${{env.PYPI_AUTH_TOKEN}}
5151

0 commit comments

Comments
 (0)