Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 6 additions & 6 deletions .github/workflows/rust-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -74,7 +74,7 @@ jobs:
with:
egress-policy: audit
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # stable
- uses: dtolnay/rust-toolchain@7e38f4b43b4db5c8dd498af069a4f6196df1d067 # stable
with:
toolchain: ${{ inputs.toolchain }}
components: rustfmt
Expand All @@ -94,7 +94,7 @@ jobs:
with:
egress-policy: audit
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # stable
- uses: dtolnay/rust-toolchain@7e38f4b43b4db5c8dd498af069a4f6196df1d067 # stable
with:
toolchain: ${{ inputs.toolchain }}
components: ${{ inputs.components }}
Expand Down Expand Up @@ -135,7 +135,7 @@ jobs:
with:
egress-policy: audit
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # stable
- uses: dtolnay/rust-toolchain@7e38f4b43b4db5c8dd498af069a4f6196df1d067 # stable
with:
toolchain: ${{ inputs.toolchain }}
components: ${{ inputs.components }}
Expand Down Expand Up @@ -163,7 +163,7 @@ jobs:
# shellcheck disable=SC2086
cargo test $FLAGS
- if: ${{ inputs.run-coverage }}
uses: taiki-e/install-action@dfae9bf3d6f6c6f20ef4ebb3486c01a51341ff12 # v2.87.18
uses: taiki-e/install-action@83ac0ad63c0167e6f06796fab0fce28db1bf3db0 # v2.87.22
with:
tool: cargo-llvm-cov
- if: ${{ inputs.run-coverage }}
Expand Down Expand Up @@ -193,10 +193,10 @@ jobs:
# based EmbarkStudios/cargo-deny-action did not respect
# rust-toolchain.toml and failed with "override toolchain not
# installed" when the consumer pinned a non-default target.
- uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # stable
- uses: dtolnay/rust-toolchain@7e38f4b43b4db5c8dd498af069a4f6196df1d067 # stable
with:
toolchain: ${{ inputs.toolchain }}
- uses: taiki-e/install-action@dfae9bf3d6f6c6f20ef4ebb3486c01a51341ff12 # v2.87.18
- uses: taiki-e/install-action@83ac0ad63c0167e6f06796fab0fce28db1bf3db0 # v2.87.22
with:
tool: cargo-deny
- run: cargo deny --all-features check
10 changes: 5 additions & 5 deletions .github/workflows/security-scan.yml
Original file line number Diff line number Diff line change
Expand Up @@ -194,11 +194,11 @@ jobs:
with:
submodules: ${{ inputs.submodules }}
- name: Initialize CodeQL
uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
languages: ${{ matrix.language }}
- name: Autobuild
uses: github/codeql-action/autobuild@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
uses: github/codeql-action/autobuild@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
- name: Analyze
# Deliberately NOT continue-on-error. This step used to carry
# `continue-on-error: true` so the default-setup collision would not
Expand All @@ -208,7 +208,7 @@ jobs:
# `languages` instead of uploading an analysis that is discarded, so
# every failure left here is a real one -- extraction faults, autobuild
# breakage, a rejected SARIF -- and a real one must fail the job.
uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
category: "/language:${{ matrix.language }}"

Expand Down Expand Up @@ -356,7 +356,7 @@ jobs:
# Security. On private repos without GHAS it 403s — don't fail the job
# over it (the scan still ran; findings are in the step log/artifact).
continue-on-error: true
uses: github/codeql-action/upload-sarif@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
uses: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
sarif_file: zizmor.sarif
category: zizmor
Expand Down Expand Up @@ -418,7 +418,7 @@ jobs:
if: always() && hashFiles('snyk.sarif') != ''
# Best-effort upload (GHAS-only); don't fail the job on no-GHAS repos.
continue-on-error: true
uses: github/codeql-action/upload-sarif@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
uses: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
sarif_file: snyk.sarif
category: snyk
Loading