diff --git a/.github/workflows/check-md-link.yml b/.github/workflows/check-md-link.yml index 093496c850..f0ffbc94e0 100644 --- a/.github/workflows/check-md-link.yml +++ b/.github/workflows/check-md-link.yml @@ -37,7 +37,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@master - - uses: gaurav-nelson/github-action-markdown-link-check@v1 + - uses: gaurav-nelson/github-action-markdown-link-check@5c5dfc0ac2e225883c0e5f03a85311ec2830d368 # v1 with: use-quiet-mode: 'yes' config-file: '.github/workflows/check-md-link-config.json' diff --git a/.github/workflows/gradle.yml b/.github/workflows/gradle.yml index 818083475d..38c88e4cf8 100644 --- a/.github/workflows/gradle.yml +++ b/.github/workflows/gradle.yml @@ -40,9 +40,9 @@ jobs: contents: read steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 - name: Set up JDK 21 - uses: actions/setup-java@v4 + uses: actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 # v4 with: java-version: '21' distribution: 'temurin' @@ -63,7 +63,7 @@ jobs: run: ./gradlew publishToMavenLocal sourceTarball - name: Archive test results - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 if: always() with: name: upload-test-artifacts @@ -75,7 +75,7 @@ jobs: # Ensure that the build works properly when building against the "latest greatest" Java version - name: Set up JDK 23 - uses: actions/setup-java@v4 + uses: actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 # v4 with: java-version: '23' distribution: 'temurin' @@ -89,7 +89,7 @@ jobs: run: ./gradlew :polaris-quarkus-service:intTest - name: Archive test results - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 if: always() with: name: upload-test-artifacts-java-23 diff --git a/.github/workflows/helm.yml b/.github/workflows/helm.yml index 6ade32f465..f18aefb893 100644 --- a/.github/workflows/helm.yml +++ b/.github/workflows/helm.yml @@ -39,12 +39,12 @@ jobs: steps: - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 with: fetch-depth: 0 - name: Set up JDK 21 - uses: actions/setup-java@v4 + uses: actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 # v4 with: java-version: '21' distribution: 'temurin' diff --git a/.github/workflows/nightly.yml b/.github/workflows/nightly.yml index 6cdd281737..99166720ad 100644 --- a/.github/workflows/nightly.yml +++ b/.github/workflows/nightly.yml @@ -46,14 +46,14 @@ jobs: if: github.repository == 'apache/polaris' steps: - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 - name: Set up JDK 21 - uses: actions/setup-java@v4 + uses: actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 # v4 with: java-version: '21' distribution: 'temurin' - name: Setup Gradle - uses: gradle/actions/setup-gradle@v4 + uses: gradle/actions/setup-gradle@8379f6a1328ee0e06e2bb424dadb7b159856a326 # v4 with: validate-wrappers: false - name: Publish SNAPSHOTs to Apache Nexus Repository diff --git a/.github/workflows/python-client.yml b/.github/workflows/python-client.yml index e64c4bdfc0..b252eb0756 100644 --- a/.github/workflows/python-client.yml +++ b/.github/workflows/python-client.yml @@ -42,10 +42,10 @@ jobs: steps: - name: Checkout Polaris project - uses: actions/checkout@v4 + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 - name: Set up Python ${{ matrix.python-version }} - uses: actions/setup-python@v5 + uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 with: python-version: ${{ matrix.python-version }} diff --git a/.github/workflows/regtest.yml b/.github/workflows/regtest.yml index c814a93665..b688a5fd64 100644 --- a/.github/workflows/regtest.yml +++ b/.github/workflows/regtest.yml @@ -32,10 +32,10 @@ jobs: contents: read steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 - name: Set up JDK 21 - uses: actions/setup-java@v4 + uses: actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 # v4 with: java-version: '21' distribution: 'temurin' diff --git a/.github/workflows/site.yml b/.github/workflows/site.yml index de458aba0b..d8f2309acd 100644 --- a/.github/workflows/site.yml +++ b/.github/workflows/site.yml @@ -29,8 +29,8 @@ jobs: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 - - uses: actions/checkout@v4 + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 with: ref: "versioned-docs" path: site/content/releases diff --git a/.github/workflows/spark_client_regtests.yml b/.github/workflows/spark_client_regtests.yml index 29de2ba6ac..87dcb003e3 100644 --- a/.github/workflows/spark_client_regtests.yml +++ b/.github/workflows/spark_client_regtests.yml @@ -32,10 +32,10 @@ jobs: contents: read steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 - name: Set up JDK 21 - uses: actions/setup-java@v4 + uses: actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 # v4 with: java-version: '21' distribution: 'temurin'