Skip to content

Commit fdf060f

Browse files
authored
Merge pull request finos#1247 from step-security-bot/stepsecurity_remediation_1720003240
[StepSecurity] ci: Harden GitHub Actions (Pinned Dependencies)
2 parents 3b6ebd5 + 70de1c4 commit fdf060f

File tree

3 files changed

+7
-7
lines changed

3 files changed

+7
-7
lines changed

.github/workflows/cve-scanning.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -28,9 +28,9 @@ jobs:
2828
matrix:
2929
node-version: [20]
3030
steps:
31-
- uses: actions/checkout@v3
31+
- uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
3232
- name: Use Node.js ${{ matrix.node-version }}
33-
uses: actions/setup-node@v3
33+
uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
3434
with:
3535
node-version: ${{ matrix.node-version }}
3636

.github/workflows/package.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -39,10 +39,10 @@ jobs:
3939

4040
steps:
4141
- name: Checkout repo
42-
uses: actions/checkout@v4
42+
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
4343

4444
- name: Use Node ${{ matrix.node }}
45-
uses: actions/setup-node@v4
45+
uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
4646
with:
4747
node-version: ${{ matrix.node }}
4848

@@ -78,10 +78,10 @@ jobs:
7878
token-name: GITHUB_TOKEN
7979
steps:
8080
- name: Checkout repo
81-
uses: actions/checkout@v4
81+
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
8282

8383
- name: Configure Node
84-
uses: actions/setup-node@v4
84+
uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
8585
with:
8686
node-version: 20
8787
registry-url: ${{ matrix.registry }}

.github/workflows/semgrep.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ jobs:
1717
container:
1818
image: returntocorp/semgrep
1919
steps:
20-
- uses: actions/checkout@v3
20+
- uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
2121
- run: semgrep scan --error --config auto
2222
env:
2323
SEMGREP_APP_TOKEN: ${{ secrets.SEMGREP_APP_TOKEN }}

0 commit comments

Comments
 (0)