Skip to content

Commit 5183d25

Browse files
committed
use signed hashes for github actions
1 parent d745624 commit 5183d25

2 files changed

Lines changed: 12 additions & 12 deletions

File tree

.github/workflows/build.yaml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -15,24 +15,24 @@ jobs:
1515
runs-on: ubuntu-latest
1616
steps:
1717
- name: Checkout repository
18-
uses: actions/checkout@v3
18+
uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # v3
1919

2020
- name: Run golangci-lint
21-
uses: reviewdog/action-golangci-lint@v2
21+
uses: reviewdog/action-golangci-lint@f9bba13753278f6a73b27a56a3ffb1bfda90ed71 # v2
2222
with:
2323
go_version: "1.25.4"
2424

2525
- name: Run hadolint
26-
uses: reviewdog/action-hadolint@v1
26+
uses: reviewdog/action-hadolint@921946a7ebaaf08ac72607bad67209f4e52b5407 # v1
2727
build:
2828
runs-on: ubuntu-latest
2929
needs: lint
3030
steps:
3131
- name: Checkout source code
32-
uses: actions/checkout@v3
32+
uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # v3
3333

3434
- name: Setup Go
35-
uses: actions/setup-go@v3
35+
uses: actions/setup-go@be3c94b385c4f180051c996d336f57a34c397495 # v3
3636
with:
3737
go-version: '1.24.3'
3838

.github/workflows/docker.yaml

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -20,33 +20,33 @@ jobs:
2020

2121
steps:
2222
- name: Checkout code
23-
uses: actions/checkout@v5
23+
uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5
2424

2525
- name: Set up QEMU
26-
uses: docker/setup-qemu-action@v3
26+
uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130 # v3
2727

2828
- name: Set up Docker Buildx
29-
uses: docker/setup-buildx-action@v3
29+
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3
3030

3131
- name: Install cosign
32-
uses: sigstore/cosign-installer@v3
32+
uses: sigstore/cosign-installer@398d4b0eeef1380460a10c8013a76f728fb906ac # v3
3333

3434
- name: Log in to GHCR
35-
uses: docker/login-action@v3
35+
uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3
3636
with:
3737
registry: ${{ env.GH_REGISTRY }}
3838
username: ${{ github.actor }}
3939
password: ${{ secrets.GITHUB_TOKEN }}
4040

4141
- name: Login to Docker Hub
42-
uses: docker/login-action@v3
42+
uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3
4343
with:
4444
username: ${{ secrets.DOCKERHUB_USERNAME }}
4545
password: ${{ secrets.DOCKERHUB_TOKEN }}
4646

4747
- name: Build and push
4848
id: buildpush
49-
uses: docker/build-push-action@v6
49+
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6
5050
with:
5151
platforms: linux/amd64,linux/arm64
5252
sbom: true

0 commit comments

Comments
 (0)