Skip to content

Commit e66f244

Browse files
authored
Merge pull request #454 from hashicorp/tsccr-auto-pinning/trusted/2023-09-11
SEC-090: Automated trusted workflow pinning (2023-09-11)
2 parents 2d49e24 + e80b3dc commit e66f244

File tree

2 files changed

+9
-9
lines changed

2 files changed

+9
-9
lines changed

.github/workflows/go-getter.yml

+6-6
Original file line numberDiff line numberDiff line change
@@ -20,12 +20,12 @@ jobs:
2020
contents: read
2121
steps:
2222
- name: Setup go
23-
uses: actions/setup-go@4d34df0c2316fe8122ab82dc22947d607c0c91f9 # v4.0.0
23+
uses: actions/setup-go@93397bea11091df50f3d7e59dc26a7711a8bcfbe # v4.1.0
2424
with:
2525
go-version: ${{ matrix.go-version }}
2626

2727
- name: Checkout code
28-
uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab # v3.5.2
28+
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
2929

3030
- name: Create test directory
3131
run: |
@@ -59,7 +59,7 @@ jobs:
5959
run: go install gotest.tools/[email protected]
6060

6161
- name: Configure AWS Credentials
62-
uses: aws-actions/configure-aws-credentials@e1e17a757e536f70e52b5a12b2e8d1d1c60e04ef # v2.0.0
62+
uses: aws-actions/configure-aws-credentials@5fd3084fc36e372ff1fff382a39b10d03659f355 # v2.2.0
6363
with:
6464
aws-region: us-east-1
6565
role-to-assume: arn:aws:iam::388664967494:role/hc-go-getter-test
@@ -103,12 +103,12 @@ jobs:
103103
run: git config --global core.autocrlf false
104104

105105
- name: Setup Go
106-
uses: actions/setup-go@4d34df0c2316fe8122ab82dc22947d607c0c91f9 # v4.0.0
106+
uses: actions/setup-go@93397bea11091df50f3d7e59dc26a7711a8bcfbe # v4.1.0
107107
with:
108108
go-version: ${{ matrix.go-version }}
109109

110110
- name: Checkout code
111-
uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab # v3.5.2
111+
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
112112

113113
- name: Setup cache for go modules
114114
uses: actions/cache@88522ab9f39a2ea568f7027eddc7d8d8bc9d59c8 # v3.3.1
@@ -128,7 +128,7 @@ jobs:
128128
run: go install gotest.tools/[email protected]
129129

130130
- name: Configure AWS Credentials
131-
uses: aws-actions/configure-aws-credentials@e1e17a757e536f70e52b5a12b2e8d1d1c60e04ef # v2.0.0
131+
uses: aws-actions/configure-aws-credentials@5fd3084fc36e372ff1fff382a39b10d03659f355 # v2.2.0
132132
with:
133133
aws-region: us-east-1
134134
role-to-assume: arn:aws:iam::388664967494:role/hc-go-getter-test

.github/workflows/release.yml

+3-3
Original file line numberDiff line numberDiff line change
@@ -16,11 +16,11 @@ jobs:
1616
runs-on: ubuntu-latest
1717
steps:
1818
- name: Checkout code
19-
uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab # v3.5.2
19+
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
2020
with:
2121
fetch-depth: 0
2222
- name: Setup go
23-
uses: actions/setup-go@4d34df0c2316fe8122ab82dc22947d607c0c91f9 # v4.0.0
23+
uses: actions/setup-go@93397bea11091df50f3d7e59dc26a7711a8bcfbe # v4.1.0
2424
with:
2525
go-version: '^1.15'
2626
- name: Setup signore
@@ -46,7 +46,7 @@ jobs:
4646
VERSION: 1.6.4
4747
SHA256SUM: 3ad66eebd443d32dd6c811dcf2d264b78678c75ed1d40c15434180d4453e60d2
4848
- name: GitHub Release
49-
uses: goreleaser/goreleaser-action@f82d6c1c344bcacabba2c841718984797f664a6b # v4.2.0
49+
uses: goreleaser/goreleaser-action@3fa32b8bb5620a2c1afe798654bbad59f9da4906 # v4.4.0
5050
with:
5151
version: latest
5252
args: release --skip-validate --timeout "60m"

0 commit comments

Comments
 (0)