diff --git a/.github/workflows/deploy.yaml b/.github/workflows/deploy.yaml index f2984f49..5eb25895 100644 --- a/.github/workflows/deploy.yaml +++ b/.github/workflows/deploy.yaml @@ -39,6 +39,6 @@ jobs: steps: - name: Deploy to GitHub Pages id: deployment - uses: actions/deploy-pages@cd2ce8fcbc39b97be8ca5fce6e763baed58fa128 # v5.0.0 + uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 # v5.0.1 with: github_token: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/fossa.yml b/.github/workflows/fossa.yml index c443c3c5..eca2475d 100644 --- a/.github/workflows/fossa.yml +++ b/.github/workflows/fossa.yml @@ -18,7 +18,7 @@ jobs: # The FOSSA token is shared between all repos in NeuVector's GH org. It can # be used directly and there is no need to request specific access to EIO. - name: Read FOSSA token - uses: rancher-eio/read-vault-secrets@dfae8acd43a9e170fca5f90168da22f814fe4e9a # v3 + uses: rancher-eio/read-vault-secrets@0da85151ad1f19ed7986c41587e45aac1ace74b6 # v3 with: secrets: | secret/data/github/org/neuvector/fossa/credentials token | FOSSA_API_KEY_PUSH_ONLY diff --git a/.github/workflows/renovate-vault.yml b/.github/workflows/renovate-vault.yml index 28c1f5b1..f64b6da0 100644 --- a/.github/workflows/renovate-vault.yml +++ b/.github/workflows/renovate-vault.yml @@ -48,7 +48,7 @@ jobs: contents: read id-token: write # Required for Vault OIDC authentication. # https://github.com/rancher/renovate-config/releases - uses: rancher/renovate-config/.github/workflows/renovate-vault.yml@a1a645d20a4c3d46bc5d1a00f45b87362fce5abc # v1.0.9 + uses: rancher/renovate-config/.github/workflows/renovate-vault.yml@8ab78fc9deaf9ca76e72718bec2954e9eaaa29a1 # v1.0.11 # Note: github.event.inputs. with '||' fallbacks is used across all inputs # so that scheduled cron runs (where github.event.inputs is null) safely default. with: