From 9c90b94bbb843ab6ba181c29f29a28572cb2154e Mon Sep 17 00:00:00 2001 From: Dan Fiedler Date: Thu, 1 Oct 2026 16:51:40 -0400 Subject: [PATCH] Pin GitHub Actions to full-length commit SHAs --- .github/dependabot.yml | 11 +++++++++++ .github/workflows/codeql.yml | 8 ++++---- .github/workflows/pr-build.yml | 6 +++--- .github/workflows/pr-security-check.yml | 16 ++++++++-------- .github/workflows/release.yml | 16 ++++++++-------- 5 files changed, 34 insertions(+), 23 deletions(-) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..2c48305 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,11 @@ +version: 2 +updates: + - package-ecosystem: "github-actions" + directory: "/" + groups: + github-actions: + patterns: ["*"] + schedule: + interval: "weekly" + cooldown: + default-days: 7 diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index ebadcfe..e1bde14 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -55,13 +55,13 @@ jobs: # your codebase is analyzed, see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages steps: - name: Checkout repository - uses: actions/checkout@v4 + uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 with: submodules: recursive # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL - uses: github/codeql-action/init@v4 + uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 with: languages: ${{ matrix.language }} build-mode: ${{ matrix.build-mode }} @@ -75,7 +75,7 @@ jobs: # Build step for C# (compiled language) — requires .NET 9 and 10 SDKs - name: Setup .NET SDK if: matrix.language == 'csharp' - uses: actions/setup-dotnet@v4 + uses: actions/setup-dotnet@67a3573c9a986a3f9c594539f4ab511d57bb3ce9 # v4.3.1 with: dotnet-version: | 9.0.x @@ -90,6 +90,6 @@ jobs: dotnet build third_party/mxc-host-prep-patch/source/MicroClaw.MxcHostPrep.csproj -p:ImportDirectoryBuildProps=false -p:ImportDirectoryBuildTargets=false - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@v4 + uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 with: category: "/language:${{matrix.language}}" diff --git a/.github/workflows/pr-build.yml b/.github/workflows/pr-build.yml index 98349de..65aef8c 100644 --- a/.github/workflows/pr-build.yml +++ b/.github/workflows/pr-build.yml @@ -41,7 +41,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v4 + uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 # Toolchain (Node 26.1+) is pre-installed on the self-hosted runner. # actions/setup-node is unreliable under the NetworkService account @@ -95,7 +95,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v4 + uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 - name: Setup Python 3.12+ uses: ./.github/actions/setup-python-windows @@ -132,7 +132,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v4 + uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 with: submodules: recursive diff --git a/.github/workflows/pr-security-check.yml b/.github/workflows/pr-security-check.yml index 4703937..d0d0494 100644 --- a/.github/workflows/pr-security-check.yml +++ b/.github/workflows/pr-security-check.yml @@ -40,8 +40,8 @@ jobs: csharp: ${{ steps.filter.outputs.csharp }} python: ${{ steps.filter.outputs.python }} steps: - - uses: actions/checkout@v4 - - uses: dorny/paths-filter@v3 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: dorny/paths-filter@0e4a8c6effa4802afeda77dc8d303f8176d7dfad # v3.0.4 id: filter with: filters: | @@ -75,10 +75,10 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v4 + uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 - name: Setup Node.js 26 - uses: actions/setup-node@v4 + uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 with: node-version: "26" @@ -126,12 +126,12 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v4 + uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 with: submodules: recursive - name: Setup .NET 9 and 10 SDKs - uses: actions/setup-dotnet@v4 + uses: actions/setup-dotnet@67a3573c9a986a3f9c594539f4ab511d57bb3ce9 # v4.3.1 with: dotnet-version: | 9.0.x @@ -186,10 +186,10 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v4 + uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 - name: Setup Python - uses: actions/setup-python@v5 + uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0 with: python-version: "3.x" diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index da3d550..d0f2cc2 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -70,7 +70,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v4 + uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 with: submodules: recursive @@ -80,19 +80,19 @@ jobs: # account). build.ps1 then installs its own npm/pip deps and locates NSIS # from electron-builder's cache. - name: Setup Node.js 26 - uses: actions/setup-node@v4 + uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 with: node-version: "26" - name: Setup .NET 9 and 10 SDKs - uses: actions/setup-dotnet@v4 + uses: actions/setup-dotnet@67a3573c9a986a3f9c594539f4ab511d57bb3ce9 # v4.3.1 with: dotnet-version: | 9.0.x 10.0.x - name: Setup Python 3.12 - uses: actions/setup-python@v5 + uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0 with: python-version: "3.12" @@ -189,14 +189,14 @@ jobs: } - name: Upload build artifact - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 with: name: MicroClawSetup path: dist\MicroClawSetup.exe if-no-files-found: error - name: Upload MSIX artifact - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 with: name: MicroClawDesktop-MSIX path: desktop\release\MicroClawDesktop-*-x64.msix @@ -205,7 +205,7 @@ jobs: # Publish a GitHub Release with the signed exe when built from a tag. - name: Publish GitHub Release if: startsWith(github.ref, 'refs/tags/v') - uses: softprops/action-gh-release@v2 + uses: softprops/action-gh-release@3bb12739c298aeb8a4eeaf626c5b8d85266b0e65 # v2.6.2 with: files: dist\MicroClawSetup.exe fail_on_unmatched_files: true @@ -213,7 +213,7 @@ jobs: - name: Publish production-identity MSIX if: startsWith(github.ref, 'refs/tags/v') && env.MSIX_PRODUCTION_IDENTITY_CONFIGURED == 'true' - uses: softprops/action-gh-release@v2 + uses: softprops/action-gh-release@3bb12739c298aeb8a4eeaf626c5b8d85266b0e65 # v2.6.2 with: files: desktop\release\MicroClawDesktop-*-x64.msix fail_on_unmatched_files: true