diff --git a/.github/workflows/k8s-diff.yaml b/.github/workflows/k8s-diff.yaml index fdb088dad..fe285d994 100644 --- a/.github/workflows/k8s-diff.yaml +++ b/.github/workflows/k8s-diff.yaml @@ -5,12 +5,12 @@ jobs: name: Base runs-on: ubuntu-latest steps: - - uses: actions/checkout@v3 + - uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # v3 with: ref: ${{ github.event.pull_request.base.sha }} - - uses: cue-lang/setup-cue@v1.0.0 + - uses: cue-lang/setup-cue@1713281ae501e533ff06108005dffeab9e2e5203 # v1.0.0 - run: cue export ./k8s/magiclove/list.cue > list.json - - uses: actions/upload-artifact@v3 + - uses: actions/upload-artifact@ff15f0306b3f739f7b6fd43fb5d26cd321bd4de5 # v3 with: name: base path: list.json @@ -18,10 +18,10 @@ jobs: name: Head runs-on: ubuntu-latest steps: - - uses: actions/checkout@v3 - - uses: cue-lang/setup-cue@v1.0.0 + - uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # v3 + - uses: cue-lang/setup-cue@1713281ae501e533ff06108005dffeab9e2e5203 # v1.0.0 - run: cue export ./k8s/magiclove/list.cue > list.json - - uses: actions/upload-artifact@v3 + - uses: actions/upload-artifact@ff15f0306b3f739f7b6fd43fb5d26cd321bd4de5 # v3 with: name: base path: list.json @@ -30,13 +30,13 @@ jobs: needs: [base, head] runs-on: ubuntu-latest steps: - - uses: actions/download-artifact@v3 - - uses: actions/setup-node@v3 + - uses: actions/download-artifact@9bc31d5ccc31df68ecc42ccf4149144866c47d8a # v3 + - uses: actions/setup-node@3235b876344d2a9aa001b8d1453c930bba69e610 # v3 with: node-version: 16 - run: npm install json-diff - name: Comment diff on PR - uses: actions/github-script@v6 + uses: actions/github-script@d7906e4ad0b1822421a7e6a35d5ca353c962f410 # v6 with: script: | const { diffString } = require("json-diff") diff --git a/.github/workflows/test.yaml b/.github/workflows/test.yaml index 90972c47c..5eedc57c4 100644 --- a/.github/workflows/test.yaml +++ b/.github/workflows/test.yaml @@ -5,6 +5,6 @@ jobs: name: Test runs-on: ubuntu-latest steps: - - uses: actions/checkout@v3 - - uses: cue-lang/setup-cue@v1.0.0 + - uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # v3 + - uses: cue-lang/setup-cue@1713281ae501e533ff06108005dffeab9e2e5203 # v1.0.0 - run: cue export ./k8s/magiclove/list.cue