From 9adcb288116b16dc2ec2189410633e27b3a8e340 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 7 Aug 2026 13:23:21 +0000 Subject: [PATCH 1/2] ci(deps): bump the github-actions group across 1 directory with 8 updates Bumps the github-actions group with 8 updates in the / directory: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.20.0` | `2.20.1` | | [actions/checkout](https://github.com/actions/checkout) | `7.0.0` | `7.0.1` | | [pnpm/action-setup](https://github.com/pnpm/action-setup) | `6.0.9` | `6.0.10` | | [actions/setup-node](https://github.com/actions/setup-node) | `6.4.0` | `7.0.0` | | [github/codeql-action/init](https://github.com/github/codeql-action) | `4.37.0` | `4.37.6` | | [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.37.0` | `4.37.6` | | [ossf/scorecard-action](https://github.com/ossf/scorecard-action) | `2.4.3` | `2.4.4` | | [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.37.0` | `4.37.6` | Updates `step-security/harden-runner` from 2.20.0 to 2.20.1 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](https://github.com/step-security/harden-runner/compare/bf7454d06d71f1098171f2acdf0cd4708d7b5920...b09bb98e06d4d774595224525879c09bc6e98c40) Updates `actions/checkout` from 7.0.0 to 7.0.1 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0...3d3c42e5aac5ba805825da76410c181273ba90b1) Updates `pnpm/action-setup` from 6.0.9 to 6.0.10 - [Release notes](https://github.com/pnpm/action-setup/releases) - [Commits](https://github.com/pnpm/action-setup/compare/0ebf47130e4866e96fce0953f49152a61190b271...0977fd99725f1db4007ccb2928dbb4e90d06cc86) Updates `actions/setup-node` from 6.4.0 to 7.0.0 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](https://github.com/actions/setup-node/compare/48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e...820762786026740c76f36085b0efc47a31fe5020) Updates `github/codeql-action/init` from 4.37.0 to 4.37.6 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/99df26d4f13ea111d4ec1a7dddef6063f76b97e9...5595ccaf912efad79be6eef63a5619ff05969be3) Updates `github/codeql-action/analyze` from 4.37.0 to 4.37.6 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/99df26d4f13ea111d4ec1a7dddef6063f76b97e9...5595ccaf912efad79be6eef63a5619ff05969be3) Updates `ossf/scorecard-action` from 2.4.3 to 2.4.4 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](https://github.com/ossf/scorecard-action/compare/4eaacf0543bb3f2c246792bd56e8cdeffafb205a...2d1146689b8cda280b9bc96326124645441f03bc) Updates `github/codeql-action/upload-sarif` from 4.37.0 to 4.37.6 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/99df26d4f13ea111d4ec1a7dddef6063f76b97e9...5595ccaf912efad79be6eef63a5619ff05969be3) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.20.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/checkout dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: pnpm/action-setup dependency-version: 6.0.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/setup-node dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: github/codeql-action/init dependency-version: 4.37.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action/analyze dependency-version: 4.37.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: ossf/scorecard-action dependency-version: 2.4.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.37.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] --- .github/workflows/architecture-boundaries.yml | 8 +++---- .github/workflows/cert-shipme.yml | 8 +++---- .github/workflows/ci.yml | 8 +++---- .github/workflows/codeql.yml | 8 +++---- .github/workflows/dependency-review.yml | 4 ++-- .github/workflows/docs-link-check.yml | 6 ++--- .github/workflows/install-bats.yml | 2 +- .github/workflows/pkg-holmes.yml | 8 +++---- .github/workflows/preflight.yml | 8 +++---- .github/workflows/release-crates.yml | 16 ++++++------- .github/workflows/rust-native.yml | 8 +++---- .github/workflows/scorecards.yml | 8 +++---- .github/workflows/wesley-holmes.yml | 24 +++++++++---------- 13 files changed, 58 insertions(+), 58 deletions(-) diff --git a/.github/workflows/architecture-boundaries.yml b/.github/workflows/architecture-boundaries.yml index 782a7f10..7dc666f0 100644 --- a/.github/workflows/architecture-boundaries.yml +++ b/.github/workflows/architecture-boundaries.yml @@ -16,20 +16,20 @@ jobs: steps: - name: Harden runner - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 + uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 with: egress-policy: audit - name: Checkout code - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 with: fetch-depth: 0 - name: Install pnpm (pinned) - uses: pnpm/action-setup@0ebf47130e4866e96fce0953f49152a61190b271 + uses: pnpm/action-setup@0977fd99725f1db4007ccb2928dbb4e90d06cc86 - name: Setup Node.js - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 with: node-version: '22' cache: 'pnpm' diff --git a/.github/workflows/cert-shipme.yml b/.github/workflows/cert-shipme.yml index 3651915d..43b5e7e4 100644 --- a/.github/workflows/cert-shipme.yml +++ b/.github/workflows/cert-shipme.yml @@ -17,12 +17,12 @@ jobs: runs-on: ubuntu-latest steps: - name: Harden runner - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 + uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 with: egress-policy: audit - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 - - uses: pnpm/action-setup@0ebf47130e4866e96fce0953f49152a61190b271 - - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 + - uses: pnpm/action-setup@0977fd99725f1db4007ccb2928dbb4e90d06cc86 + - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 with: { node-version: 22, cache: 'pnpm' } - run: pnpm install --frozen-lockfile - name: Verify lockfile unchanged diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index eca679c5..c75a5595 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -11,18 +11,18 @@ jobs: timeout-minutes: 20 steps: - name: Harden runner - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 + uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 with: egress-policy: audit - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 with: submodules: recursive - - uses: pnpm/action-setup@0ebf47130e4866e96fce0953f49152a61190b271 + - uses: pnpm/action-setup@0977fd99725f1db4007ccb2928dbb4e90d06cc86 - name: Verify pnpm version run: | echo "pnpm: $(pnpm --version)" node -v - - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e + - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 with: { node-version: 22, cache: 'pnpm' } - run: pnpm install --frozen-lockfile - name: Verify lockfile unchanged diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 9a127660..a7a47d4e 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -27,21 +27,21 @@ jobs: steps: - name: Harden runner - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 + uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 with: egress-policy: audit - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 - name: Initialize CodeQL - uses: github/codeql-action/init@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 + uses: github/codeql-action/init@5595ccaf912efad79be6eef63a5619ff05969be3 with: languages: ${{ matrix.language }} build-mode: none queries: security-and-quality - name: Analyze with CodeQL - uses: github/codeql-action/analyze@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 + uses: github/codeql-action/analyze@5595ccaf912efad79be6eef63a5619ff05969be3 with: category: /language:${{ matrix.language }} diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index a798c3be..fea34cc8 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -17,12 +17,12 @@ jobs: steps: - name: Harden runner - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 + uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 with: egress-policy: audit - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 - name: Review dependencies uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 diff --git a/.github/workflows/docs-link-check.yml b/.github/workflows/docs-link-check.yml index 4323e815..8e9cfb49 100644 --- a/.github/workflows/docs-link-check.yml +++ b/.github/workflows/docs-link-check.yml @@ -20,11 +20,11 @@ jobs: runs-on: ubuntu-latest steps: - name: Harden runner - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 + uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 with: egress-policy: audit - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 - - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 + - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 with: node-version: 22 - name: Check markdown links (relative only) diff --git a/.github/workflows/install-bats.yml b/.github/workflows/install-bats.yml index b5f908d6..9f4f02c8 100644 --- a/.github/workflows/install-bats.yml +++ b/.github/workflows/install-bats.yml @@ -11,7 +11,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Harden runner - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 + uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 with: egress-policy: audit - name: Install bats and jq diff --git a/.github/workflows/pkg-holmes.yml b/.github/workflows/pkg-holmes.yml index 0c6e004f..df38136c 100644 --- a/.github/workflows/pkg-holmes.yml +++ b/.github/workflows/pkg-holmes.yml @@ -21,12 +21,12 @@ jobs: timeout-minutes: 10 steps: - name: Harden runner - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 + uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 with: egress-policy: audit - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 - - uses: pnpm/action-setup@0ebf47130e4866e96fce0953f49152a61190b271 - - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 + - uses: pnpm/action-setup@0977fd99725f1db4007ccb2928dbb4e90d06cc86 + - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 with: node-version: 22 - name: Enable corepack (pnpm) diff --git a/.github/workflows/preflight.yml b/.github/workflows/preflight.yml index 7d2c599f..ab9cfdf4 100644 --- a/.github/workflows/preflight.yml +++ b/.github/workflows/preflight.yml @@ -15,14 +15,14 @@ jobs: runs-on: ubuntu-latest steps: - name: Harden runner - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 + uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 with: egress-policy: audit - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 - - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 + - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 with: node-version: 22 - - uses: pnpm/action-setup@0ebf47130e4866e96fce0953f49152a61190b271 + - uses: pnpm/action-setup@0977fd99725f1db4007ccb2928dbb4e90d06cc86 - name: Verify pnpm version run: | echo "pnpm: $(pnpm --version)" diff --git a/.github/workflows/release-crates.yml b/.github/workflows/release-crates.yml index 3b00084f..31927576 100644 --- a/.github/workflows/release-crates.yml +++ b/.github/workflows/release-crates.yml @@ -20,12 +20,12 @@ jobs: timeout-minutes: 30 steps: - name: Harden runner - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 + uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 with: egress-policy: audit - name: Checkout release tag - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 with: fetch-depth: 0 @@ -35,10 +35,10 @@ jobs: cargo --version - name: Install pnpm - uses: pnpm/action-setup@0ebf47130e4866e96fce0953f49152a61190b271 + uses: pnpm/action-setup@0977fd99725f1db4007ccb2928dbb4e90d06cc86 - name: Setup Node.js - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 with: node-version: 22 cache: 'pnpm' @@ -132,12 +132,12 @@ jobs: issues: read steps: - name: Harden runner - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 + uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 with: egress-policy: audit - name: Checkout release tag - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 with: fetch-depth: 0 @@ -152,10 +152,10 @@ jobs: fi - name: Install pnpm - uses: pnpm/action-setup@0ebf47130e4866e96fce0953f49152a61190b271 + uses: pnpm/action-setup@0977fd99725f1db4007ccb2928dbb4e90d06cc86 - name: Setup Node.js - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 with: node-version: 22 cache: 'pnpm' diff --git a/.github/workflows/rust-native.yml b/.github/workflows/rust-native.yml index 4d7d0e2a..79ae6d40 100644 --- a/.github/workflows/rust-native.yml +++ b/.github/workflows/rust-native.yml @@ -51,16 +51,16 @@ jobs: runs-on: ubuntu-latest steps: - name: Harden runner - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 + uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 with: egress-policy: audit - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 - name: Verify Rust toolchain run: | rustc --version cargo --version - - uses: pnpm/action-setup@0ebf47130e4866e96fce0953f49152a61190b271 - - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e + - uses: pnpm/action-setup@0977fd99725f1db4007ccb2928dbb4e90d06cc86 + - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 with: node-version: 22 cache: 'pnpm' diff --git a/.github/workflows/scorecards.yml b/.github/workflows/scorecards.yml index 74a2b021..6ae78646 100644 --- a/.github/workflows/scorecards.yml +++ b/.github/workflows/scorecards.yml @@ -22,24 +22,24 @@ jobs: security-events: write steps: - name: Harden runner - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 + uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 with: egress-policy: audit - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 with: fetch-depth: 0 - name: Run Scorecard id: scorecard - uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a + uses: ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc with: results_file: results.sarif results_format: sarif publish_results: true - name: Upload Results to GitHub Security tab - uses: github/codeql-action/upload-sarif@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 + uses: github/codeql-action/upload-sarif@5595ccaf912efad79be6eef63a5619ff05969be3 with: sarif_file: results.sarif diff --git a/.github/workflows/wesley-holmes.yml b/.github/workflows/wesley-holmes.yml index 6c93df8c..907ceb3f 100644 --- a/.github/workflows/wesley-holmes.yml +++ b/.github/workflows/wesley-holmes.yml @@ -26,12 +26,12 @@ jobs: steps: - name: Harden runner - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 + uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 with: egress-policy: audit - name: '📦 Checkout Repository' - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 with: fetch-depth: 0 @@ -146,12 +146,12 @@ jobs: steps: - name: Harden runner - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 + uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 with: egress-policy: audit - name: '📦 Checkout Repository' - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 with: fetch-depth: 0 @@ -202,12 +202,12 @@ jobs: steps: - name: Harden runner - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 + uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 with: egress-policy: audit - name: '📦 Checkout Repository' - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 - name: '🛠️ Setup HOLMES environment' uses: ./.github/actions/holmes-setup @@ -254,12 +254,12 @@ jobs: steps: - name: Harden runner - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 + uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 with: egress-policy: audit - name: '📦 Checkout Repository' - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 - name: '🛠️ Setup HOLMES environment' uses: ./.github/actions/holmes-setup @@ -306,12 +306,12 @@ jobs: steps: - name: Harden runner - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 + uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 with: egress-policy: audit - name: '📦 Checkout Repository' - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 with: fetch-depth: 0 @@ -483,12 +483,12 @@ jobs: steps: - name: Harden runner - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 + uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 with: egress-policy: audit - name: '📦 Checkout Repository' - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 - name: '📥 Download Reports' uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c with: From a8343fe75fca5aa15fe8003e61f325f79368c88d Mon Sep 17 00:00:00 2001 From: James Ross Date: Thu, 27 Aug 2026 04:37:06 -0700 Subject: [PATCH 2/2] test(ci): track updated GitHub Action pins --- test/ci-workflows.bats | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/test/ci-workflows.bats b/test/ci-workflows.bats index 72c20264..dd2e32b8 100644 --- a/test/ci-workflows.bats +++ b/test/ci-workflows.bats @@ -60,11 +60,11 @@ load 'vendor/bats-plugins/bats-assert/load' assert_success [ "$output" -eq 2 ] - run bash -lc "grep -F 'pnpm/action-setup@0ebf47130e4866e96fce0953f49152a61190b271' .github/workflows/rust-native.yml | wc -l" + run bash -lc "grep -F 'pnpm/action-setup@0977fd99725f1db4007ccb2928dbb4e90d06cc86' .github/workflows/rust-native.yml | wc -l" assert_success [ "$output" -eq 1 ] - run bash -lc "grep -F 'actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e' .github/workflows/rust-native.yml | wc -l" + run bash -lc "grep -F 'actions/setup-node@820762786026740c76f36085b0efc47a31fe5020' .github/workflows/rust-native.yml | wc -l" assert_success [ "$output" -eq 1 ] @@ -77,11 +77,11 @@ load 'vendor/bats-plugins/bats-assert/load' } @test "release crates provisions pnpm before preflight-backed commands" { - run bash -lc "grep -F 'pnpm/action-setup@0ebf47130e4866e96fce0953f49152a61190b271' .github/workflows/release-crates.yml | wc -l" + run bash -lc "grep -F 'pnpm/action-setup@0977fd99725f1db4007ccb2928dbb4e90d06cc86' .github/workflows/release-crates.yml | wc -l" assert_success [ "$output" -eq 2 ] - run bash -lc "grep -F 'actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e' .github/workflows/release-crates.yml | wc -l" + run bash -lc "grep -F 'actions/setup-node@820762786026740c76f36085b0efc47a31fe5020' .github/workflows/release-crates.yml | wc -l" assert_success [ "$output" -eq 2 ] @@ -585,7 +585,7 @@ load 'vendor/bats-plugins/bats-assert/load' } @test "wesley-holmes workflow builds PR comments via the Holmes comment builder" { - run bash -lc "grep -A80 '^ comment-report:' .github/workflows/wesley-holmes.yml | grep -F 'actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0' | wc -l" + run bash -lc "grep -A80 '^ comment-report:' .github/workflows/wesley-holmes.yml | grep -F 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1' | wc -l" assert_success [ "$output" -eq 1 ]