diff --git a/.github/workflows/check-dist.yml b/.github/workflows/check-dist.yml index 6c2ee32..f28fd53 100644 --- a/.github/workflows/check-dist.yml +++ b/.github/workflows/check-dist.yml @@ -29,10 +29,10 @@ jobs: steps: - name: Setup Bolt - uses: koalalab-inc/bolt@7bc45c5036a248828c82447f9bb3fea35fe27c93 # koalalab-inc/bolt@v1.3.0 | main + uses: koalalab-inc/bolt@b7388cf6657068ee4d2b324a7a530a7ce203fd36 # koalalab-inc/bolt@v1.3.0 | main - name: Checkout id: checkout - uses: actions/checkout@9bb56186c3b09b4f86b1c65136769dd318469633 # actions/checkout@v4 | 1567,v4.1.2 + uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # actions/checkout@v4 | 1567,v4.1.7 - name: Setup Node.js id: setup-node @@ -64,7 +64,7 @@ jobs: - if: ${{ failure() && steps.diff.outcome == 'failure' }} name: Upload Artifact id: upload - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # actions/upload-artifact@v4 | v4.3.4 + uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # actions/upload-artifact@v4 | v4.4.0 with: name: dist path: dist/ diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 0906417..98367a7 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -16,10 +16,10 @@ jobs: steps: - name: Setup Bolt - uses: koalalab-inc/bolt@7bc45c5036a248828c82447f9bb3fea35fe27c93 # koalalab-inc/bolt@v1.3.0 | main + uses: koalalab-inc/bolt@b7388cf6657068ee4d2b324a7a530a7ce203fd36 # koalalab-inc/bolt@v1.3.0 | main - name: Checkout id: checkout - uses: actions/checkout@9bb56186c3b09b4f86b1c65136769dd318469633 # actions/checkout@v4 | 1567,v4.1.2 + uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # actions/checkout@v4 | 1567,v4.1.7 - name: Setup Node.js id: setup-node @@ -50,7 +50,7 @@ jobs: steps: - name: Setup Bolt - uses: koalalab-inc/bolt@7bc45c5036a248828c82447f9bb3fea35fe27c93 # koalalab-inc/bolt@v1.3.0 | main + uses: koalalab-inc/bolt@b7388cf6657068ee4d2b324a7a530a7ce203fd36 # koalalab-inc/bolt@v1.3.0 | main - name: Checkout id: checkout - uses: actions/checkout@9bb56186c3b09b4f86b1c65136769dd318469633 # actions/checkout@v4 | 1567,v4.1.2 + uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # actions/checkout@v4 | 1567,v4.1.7 diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index b913e08..bd1cdf5 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -54,7 +54,7 @@ jobs: # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL - uses: github/codeql-action/init@afb54ba388a7dca6ecae48f608c4ff05ff4cc77a # github/codeql-action/init@v3 + uses: github/codeql-action/init@4dd16135b69a43b6c8efb853346f8437d92d3c93 # github/codeql-action/init@v3 with: config-file: ./.github/codeql/codeql-config.yml languages: ${{ matrix.language }} @@ -82,6 +82,6 @@ jobs: # exit 1 - name: Perform CodeQL Analysis - uses: github/codeql-action/init@afb54ba388a7dca6ecae48f608c4ff05ff4cc77a # github/codeql-action/init@v3 + uses: github/codeql-action/init@4dd16135b69a43b6c8efb853346f8437d92d3c93 # github/codeql-action/init@v3 with: category: "/language:${{matrix.language}}" diff --git a/.github/workflows/linter.yml b/.github/workflows/linter.yml index 4515579..24f3eb2 100644 --- a/.github/workflows/linter.yml +++ b/.github/workflows/linter.yml @@ -19,10 +19,10 @@ jobs: steps: - name: Setup Bolt - uses: koalalab-inc/bolt@7bc45c5036a248828c82447f9bb3fea35fe27c93 # koalalab-inc/bolt@v1.3.0 | main + uses: koalalab-inc/bolt@b7388cf6657068ee4d2b324a7a530a7ce203fd36 # koalalab-inc/bolt@v1.3.0 | main - name: Checkout id: checkout - uses: actions/checkout@9bb56186c3b09b4f86b1c65136769dd318469633 # actions/checkout@v4 | 1567,v4.1.2 + uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # actions/checkout@v4 | 1567,v4.1.7 with: fetch-depth: 0 diff --git a/.github/workflows/ossf-scorecard.yml b/.github/workflows/ossf-scorecard.yml index b44d9d9..a555a11 100644 --- a/.github/workflows/ossf-scorecard.yml +++ b/.github/workflows/ossf-scorecard.yml @@ -28,7 +28,7 @@ jobs: steps: - name: "Checkout code" - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1 + uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7 with: persist-credentials: false @@ -55,7 +55,7 @@ jobs: # Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF # format to the repository Actions tab. - name: "Upload artifact" - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # actions/upload-artifact@v4 | main,v4.3.4 + uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # actions/upload-artifact@v4 | main,v4.4.0 with: name: SARIF file path: results.sarif diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 2da0837..81a7b2c 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -21,9 +21,9 @@ jobs: hashes: ${{ steps.hash.outputs.hashes }} steps: - name: Setup Bolt - uses: koalalab-inc/bolt@7bc45c5036a248828c82447f9bb3fea35fe27c93 # koalalab-inc/bolt@v1.3.0 | main + uses: koalalab-inc/bolt@b7388cf6657068ee4d2b324a7a530a7ce203fd36 # koalalab-inc/bolt@v1.3.0 | main - name: Checkout - uses: actions/checkout@9bb56186c3b09b4f86b1c65136769dd318469633 # actions/checkout@v4 | 1567,v4.1.2 + uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # actions/checkout@v4 | 1567,v4.1.7 - name: Get release version id: releaseVersion shell: bash @@ -49,7 +49,7 @@ jobs: rm -rf mitmproxy bolt rm mitmproxy-10.2.2-linux-x86_64.tar.gz - name: Install Cosign - uses: sigstore/cosign-installer@59acb6260d9c0ba8f4a2f9d9b48431a222b68e20 # sigstore/cosign-installer@v3.5.0 + uses: sigstore/cosign-installer@4959ce089c160fddf62f7b42464195ba1a56d382 # sigstore/cosign-installer@v3.6.0 with: cosign-release: 'v2.2.4' # optional - name: Sign Release @@ -75,7 +75,7 @@ jobs: bolt-${{ env.tag }}-${{ env.os }}-${{ env.arch }}.tar.gz.cert | base64 -w0)" >> "$GITHUB_OUTPUT" - name: Upload tarball - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # actions/upload-artifact@v4 | main,v4.3.4 + uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # actions/upload-artifact@v4 | main,v4.4.0 with: name: bolt-${{ env.tag }}-${{ env.os }}-${{ env.arch }}.tar.gz path: bolt-${{ env.tag }}-${{ env.os }}-${{ env.arch }}.tar.gz @@ -83,7 +83,7 @@ jobs: retention-days: 5 - name: Upload signature - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # actions/upload-artifact@v4 | main,v4.3.4 + uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # actions/upload-artifact@v4 | main,v4.4.0 with: name: bolt-${{ env.tag }}-${{ env.os }}-${{ env.arch }}.tar.gz.sig path: bolt-${{ env.tag }}-${{ env.os }}-${{ env.arch }}.tar.gz.sig @@ -91,7 +91,7 @@ jobs: retention-days: 5 - name: Upload certificate - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # actions/upload-artifact@v4 | main,v4.3.4 + uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # actions/upload-artifact@v4 | main,v4.4.0 with: name: bolt-${{ env.tag }}-${{ env.os }}-${{ env.arch }}.tar.gz.cert path: bolt-${{ env.tag }}-${{ env.os }}-${{ env.arch }}.tar.gz.cert @@ -99,7 +99,7 @@ jobs: retention-days: 5 - name: Upload verification bundle - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # actions/upload-artifact@v4 | main,v4.3.4 + uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # actions/upload-artifact@v4 | main,v4.4.0 with: name: bolt-${{ env.tag }}-${{ env.os }}-${{ env.arch }}.tar.gz.bundle path: bolt-${{ env.tag }}-${{ env.os }}-${{ env.arch }}.tar.gz.bundle @@ -150,7 +150,7 @@ jobs: name: bolt-${{ env.tag }}-${{ env.os }}-${{ env.arch }}.tar.gz.bundle - name: Install Cosign - uses: sigstore/cosign-installer@59acb6260d9c0ba8f4a2f9d9b48431a222b68e20 # sigstore/cosign-installer@v3.5.0 + uses: sigstore/cosign-installer@4959ce089c160fddf62f7b42464195ba1a56d382 # sigstore/cosign-installer@v3.6.0 with: cosign-release: 'v2.2.4' # optional