diff --git a/.github/workflows/CI.yml b/.github/workflows/CI.yml index ae8a4bc0ea..8b3ce1689c 100644 --- a/.github/workflows/CI.yml +++ b/.github/workflows/CI.yml @@ -20,7 +20,7 @@ jobs: outputs: RUN_BUILD_AND_TEST: ${{ steps.check.outputs.files_changed }} steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - name: Check files id: check uses: ./.github/actions/check-files @@ -30,7 +30,7 @@ jobs: Get-CI-Image-Tag: needs: check-files if: needs.check-files.outputs.RUN_BUILD_AND_TEST == 'true' - uses: opensearch-project/opensearch-build/.github/workflows/get-ci-image-tag.yml@main + uses: opensearch-project/opensearch-build/.github/workflows/get-ci-image-tag.yml@c2498b758c08fb7bc48476509a5fc1b8dd5f7493 # main with: product: opensearch @@ -59,7 +59,7 @@ jobs: run: ${{ needs.Get-CI-Image-Tag.outputs.ci-image-start-command }} - name: Checkout k-NN - uses: actions/checkout@v4 + uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 # Setup git user so that patches for native libraries can be applied and committed - name: Setup git user @@ -68,7 +68,7 @@ jobs: su `id -un 1000` -c 'git config --global user.email "github-actions[bot]@users.noreply.github.com"' - name: Setup Java ${{ matrix.java }} - uses: actions/setup-java@v4 + uses: actions/setup-java@c1e323688fd81a25caa38c78aa6df2d33d3e20d9 # v4 with: java-version: ${{ matrix.java }} distribution: 'temurin' @@ -98,7 +98,7 @@ jobs: - name: Upload Coverage Report - uses: codecov/codecov-action@v5 + uses: codecov/codecov-action@75cd11691c0faa626561e295848008c8a7dddffe # v5 with: token: ${{ secrets.CODECOV_TOKEN }} use_pypi: true @@ -114,7 +114,7 @@ jobs: steps: - name: Checkout k-NN - uses: actions/checkout@v4 + uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 # Setup git user so that patches for native libraries can be applied and committed - name: Setup git user @@ -123,7 +123,7 @@ jobs: git config --global user.email "github-actions[bot]@users.noreply.github.com" - name: Setup Java ${{ matrix.java }} - uses: actions/setup-java@v4 + uses: actions/setup-java@c1e323688fd81a25caa38c78aa6df2d33d3e20d9 # v4 with: java-version: ${{ matrix.java }} distribution: 'temurin' @@ -157,7 +157,7 @@ jobs: steps: - name: Checkout k-NN - uses: actions/checkout@v4 + uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 # Setup git user so that patches for native libraries can be applied and committed - name: Setup git user @@ -166,7 +166,7 @@ jobs: git config --global user.email "github-actions[bot]@users.noreply.github.com" - name: Setup Java ${{ matrix.java }} - uses: actions/setup-java@v4 + uses: actions/setup-java@c1e323688fd81a25caa38c78aa6df2d33d3e20d9 # v4 with: java-version: ${{ matrix.java }} distribution: 'temurin' diff --git a/.github/workflows/auto-release.yml b/.github/workflows/auto-release.yml index c67e12badb..8505a552aa 100644 --- a/.github/workflows/auto-release.yml +++ b/.github/workflows/auto-release.yml @@ -13,16 +13,16 @@ jobs: steps: - name: GitHub App token id: github_app_token - uses: tibdex/github-app-token@v1.5.0 + uses: tibdex/github-app-token@1901dc7d52169e70c27a8da37aef0d423e2867a2 # v1.5.0 with: app_id: ${{ secrets.APP_ID }} private_key: ${{ secrets.APP_PRIVATE_KEY }} installation_id: 22958780 - name: Get tag id: tag - uses: dawidd6/action-get-tag@v1 - - uses: actions/checkout@v2 - - uses: ncipollo/release-action@v1 + uses: dawidd6/action-get-tag@727a6f0a561be04e09013531e73a3983a65e3479 # v1 + - uses: actions/checkout@ee0669bd1cc54295c223e0bb666b733df41de1c5 # v2 + - uses: ncipollo/release-action@339a81892b84b4eeb0f6e744e4574d79d0d9b8dd # v1 with: github_token: ${{ steps.github_app_token.outputs.token }} bodyFile: release-notes/opensearch-knn.release-notes-${{steps.tag.outputs.tag}}.md diff --git a/.github/workflows/backport.yml b/.github/workflows/backport.yml index e47d8d88c0..2609a3c460 100644 --- a/.github/workflows/backport.yml +++ b/.github/workflows/backport.yml @@ -15,14 +15,14 @@ jobs: steps: - name: GitHub App token id: github_app_token - uses: tibdex/github-app-token@v1.5.0 + uses: tibdex/github-app-token@1901dc7d52169e70c27a8da37aef0d423e2867a2 # v1.5.0 with: app_id: ${{ secrets.APP_ID }} private_key: ${{ secrets.APP_PRIVATE_KEY }} installation_id: 22958780 - name: Backport - uses: VachaShah/backport@v1.1.4 + uses: VachaShah/backport@28c49d91ceec57d7c9f625f1031c1a4d637251f5 # v1.1.4 with: github_token: ${{ steps.github_app_token.outputs.token }} branch_name: backport/backport-${{ github.event.number }} diff --git a/.github/workflows/backwards_compatibility_tests_workflow.yml b/.github/workflows/backwards_compatibility_tests_workflow.yml index 5429ddbb42..0db4b36f88 100644 --- a/.github/workflows/backwards_compatibility_tests_workflow.yml +++ b/.github/workflows/backwards_compatibility_tests_workflow.yml @@ -54,7 +54,7 @@ jobs: steps: - name: Checkout k-NN - uses: actions/checkout@v1 + uses: actions/checkout@50fbc622fc4ef5163becd7fab6573eac35f8462e # v1 # Setup git user so that patches for native libraries can be applied and committed - name: Setup git user @@ -63,7 +63,7 @@ jobs: git config --global user.email "github-actions[bot]@users.noreply.github.com" - name: Setup Java ${{ matrix.java }} - uses: actions/setup-java@v1 + uses: actions/setup-java@b6e674f4b717d7b0ae3baee0fbe79f498905dfde # v1 with: java-version: ${{ matrix.java }} @@ -140,7 +140,7 @@ jobs: steps: - name: Checkout k-NN - uses: actions/checkout@v1 + uses: actions/checkout@50fbc622fc4ef5163becd7fab6573eac35f8462e # v1 # Setup git user so that patches for native libraries can be applied and committed - name: Setup git user @@ -149,7 +149,7 @@ jobs: git config --global user.email "github-actions[bot]@users.noreply.github.com" - name: Setup Java ${{ matrix.java }} - uses: actions/setup-java@v1 + uses: actions/setup-java@b6e674f4b717d7b0ae3baee0fbe79f498905dfde # v1 with: java-version: ${{ matrix.java }} diff --git a/.github/workflows/changelog_verifier.yml b/.github/workflows/changelog_verifier.yml index 791c02ab70..3c2a2060cc 100644 --- a/.github/workflows/changelog_verifier.yml +++ b/.github/workflows/changelog_verifier.yml @@ -8,11 +8,11 @@ jobs: verify-changelog: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v3 + - uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # v3 with: token: ${{ secrets.GITHUB_TOKEN }} ref: ${{ github.event.pull_request.head.sha }} - - uses: dangoslen/changelog-enforcer@v3 + - uses: dangoslen/changelog-enforcer@204e7d3ef26579f4cd0fd759c57032656fdf23c7 # v3 with: skipLabels: "autocut, skip-changelog" diff --git a/.github/workflows/create-documentation-issue.yml b/.github/workflows/create-documentation-issue.yml index 1ab6e8b15c..af2b9f2cad 100644 --- a/.github/workflows/create-documentation-issue.yml +++ b/.github/workflows/create-documentation-issue.yml @@ -14,14 +14,14 @@ jobs: steps: - name: GitHub App token id: github_app_token - uses: tibdex/github-app-token@v1.5.0 + uses: tibdex/github-app-token@1901dc7d52169e70c27a8da37aef0d423e2867a2 # v1.5.0 with: app_id: ${{ secrets.APP_ID }} private_key: ${{ secrets.APP_PRIVATE_KEY }} installation_id: 22958780 - name: Checkout code - uses: actions/checkout@v2 + uses: actions/checkout@ee0669bd1cc54295c223e0bb666b733df41de1c5 # v2 - name: Edit the issue template run: | @@ -29,7 +29,7 @@ jobs: - name: Create Issue From File id: create-issue - uses: peter-evans/create-issue-from-file@v4 + uses: peter-evans/create-issue-from-file@433e51abf769039ee20ba1293a088ca19d573b7f # v4 with: title: Add documentation related to new feature content-filepath: ./.github/ISSUE_TEMPLATE/documentation-issue.md diff --git a/.github/workflows/delete_backport_branch.yml b/.github/workflows/delete_backport_branch.yml index a4d186ca79..0ff2f7b704 100644 --- a/.github/workflows/delete_backport_branch.yml +++ b/.github/workflows/delete_backport_branch.yml @@ -12,7 +12,7 @@ jobs: if: github.repository == 'opensearch-project/k-NN' && startsWith(github.event.pull_request.head.ref,'backport/') steps: - name: Delete merged branch - uses: actions/github-script@v7 + uses: actions/github-script@f28e40c7f34bde8b3046d885e986cb6290c5673b # v7 with: script: | github.rest.git.deleteRef({ diff --git a/.github/workflows/draft-release-notes-workflow.yml b/.github/workflows/draft-release-notes-workflow.yml index 6b3d89c33c..48e2bf97aa 100644 --- a/.github/workflows/draft-release-notes-workflow.yml +++ b/.github/workflows/draft-release-notes-workflow.yml @@ -11,7 +11,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Update draft release notes - uses: release-drafter/release-drafter@v5 + uses: release-drafter/release-drafter@09c613e259eb8d4e7c81c2cb00618eb5fc4575a7 # v5 with: config-name: draft-release-notes-config.yml name: Version (set here) diff --git a/.github/workflows/issue-dedupe.yml b/.github/workflows/issue-dedupe.yml index 6a7c78627f..10cd4ab5ac 100644 --- a/.github/workflows/issue-dedupe.yml +++ b/.github/workflows/issue-dedupe.yml @@ -20,7 +20,7 @@ jobs: (github.event_name == 'issues' && github.event.issue.user.type != 'Bot' && github.repository == 'opensearch-project/k-NN') - uses: opensearch-project/opensearch-build/.github/workflows/issue-dedupe-detect.yml@main + uses: opensearch-project/opensearch-build/.github/workflows/issue-dedupe-detect.yml@c2498b758c08fb7bc48476509a5fc1b8dd5f7493 # main permissions: contents: read issues: write @@ -33,7 +33,7 @@ jobs: auto-close-issue: if: github.event_name == 'schedule' && github.repository == 'opensearch-project/k-NN' - uses: opensearch-project/opensearch-build/.github/workflows/issue-dedupe-autoclose.yml@main + uses: opensearch-project/opensearch-build/.github/workflows/issue-dedupe-autoclose.yml@c2498b758c08fb7bc48476509a5fc1b8dd5f7493 # main permissions: issues: write with: diff --git a/.github/workflows/links.yml b/.github/workflows/links.yml index 3d0b81ad5f..88f0d32121 100644 --- a/.github/workflows/links.yml +++ b/.github/workflows/links.yml @@ -11,10 +11,10 @@ jobs: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v2 + - uses: actions/checkout@ee0669bd1cc54295c223e0bb666b733df41de1c5 # v2 - name: lychee Link Checker id: lychee - uses: lycheeverse/lychee-action@master + uses: lycheeverse/lychee-action@6da1d14f3a43098a294b7696d93d938aa8d20fc0 # master with: args: --accept=200,403,429 **/*.html **/*.md **/*.txt **/*.json env: diff --git a/.github/workflows/maven-publish.yml b/.github/workflows/maven-publish.yml index 7c33a35fad..c7c792e34c 100644 --- a/.github/workflows/maven-publish.yml +++ b/.github/workflows/maven-publish.yml @@ -17,14 +17,14 @@ jobs: contents: write steps: - - uses: actions/setup-java@v3 + - uses: actions/setup-java@17f84c3641ba7b8f6deff6309fc4c864478f5d62 # v3 with: distribution: temurin # Temurin is a distribution of adoptium java-version: 21 - - uses: actions/checkout@v3 + - uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # v3 - name: Load secret - uses: 1password/load-secrets-action@v2 + uses: 1password/load-secrets-action@581a835fb51b8e7ec56b71cf2ffddd7e68bb25e0 # v2 with: # Export loaded secrets as environment variables export-env: true @@ -34,7 +34,7 @@ jobs: MAVEN_SNAPSHOTS_S3_ROLE: op://opensearch-infra-secrets/maven-snapshots-s3/role - name: Configure AWS credentials - uses: aws-actions/configure-aws-credentials@v5 + uses: aws-actions/configure-aws-credentials@61815dcd50bd041e203e49132bacad1fd04d2708 # v5 with: role-to-assume: ${{ env.MAVEN_SNAPSHOTS_S3_ROLE }} aws-region: us-east-1 diff --git a/.github/workflows/pr_review.yml b/.github/workflows/pr_review.yml index 7939008645..ba73e64567 100644 --- a/.github/workflows/pr_review.yml +++ b/.github/workflows/pr_review.yml @@ -6,7 +6,7 @@ on: jobs: Code-Diff-Analyzer: - uses: opensearch-project/opensearch-build/.github/workflows/code-diff-analyzer.yml@main + uses: opensearch-project/opensearch-build/.github/workflows/code-diff-analyzer.yml@c2498b758c08fb7bc48476509a5fc1b8dd5f7493 # main if: github.repository == 'opensearch-project/k-NN' permissions: id-token: write # github oidc to assume aws roles @@ -18,7 +18,7 @@ jobs: update_pr_comment_with_analyzer_report: true Code-Diff-Reviewer: - uses: opensearch-project/opensearch-build/.github/workflows/code-diff-reviewer.yml@main + uses: opensearch-project/opensearch-build/.github/workflows/code-diff-reviewer.yml@c2498b758c08fb7bc48476509a5fc1b8dd5f7493 # main needs: Code-Diff-Analyzer if: github.repository == 'opensearch-project/k-NN' permissions: diff --git a/.github/workflows/remote_index_build.yml b/.github/workflows/remote_index_build.yml index a9c5999edf..897cd2f7d7 100644 --- a/.github/workflows/remote_index_build.yml +++ b/.github/workflows/remote_index_build.yml @@ -18,7 +18,7 @@ jobs: outputs: RUN_IT_TEST: ${{ steps.check.outputs.files_changed }} steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - name: Check files id: check uses: ./.github/actions/check-files @@ -45,7 +45,7 @@ jobs: steps: - name: Checkout k-NN - uses: actions/checkout@v4 + uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 # Setup git user so that patches for native libraries can be applied and committed - name: Setup git user @@ -54,7 +54,7 @@ jobs: git config --global user.email "github-actions[bot]@users.noreply.github.com" - name: Setup Java ${{ matrix.java }} - uses: actions/setup-java@v4 + uses: actions/setup-java@c1e323688fd81a25caa38c78aa6df2d33d3e20d9 # v4 with: java-version: ${{ matrix.java }} distribution: 'temurin' diff --git a/.github/workflows/test_security.yml b/.github/workflows/test_security.yml index 65953e8e22..51d0bd5b95 100644 --- a/.github/workflows/test_security.yml +++ b/.github/workflows/test_security.yml @@ -18,7 +18,7 @@ jobs: outputs: RUN_SECURE_IT_TEST: ${{ steps.check.outputs.files_changed }} steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - name: Check files id: check uses: ./.github/actions/check-files @@ -28,7 +28,7 @@ jobs: Get-CI-Image-Tag: needs: check-files if: needs.check-files.outputs.RUN_SECURE_IT_TEST == 'true' - uses: opensearch-project/opensearch-build/.github/workflows/get-ci-image-tag.yml@main + uses: opensearch-project/opensearch-build/.github/workflows/get-ci-image-tag.yml@c2498b758c08fb7bc48476509a5fc1b8dd5f7493 # main with: product: opensearch @@ -55,7 +55,7 @@ jobs: - name: Run start commands run: ${{ needs.Get-CI-Image-Tag.outputs.ci-image-start-command }} - name: Checkout k-NN - uses: actions/checkout@v4 + uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 # Setup git user so that patches for native libraries can be applied and committed - name: Setup git user run: | @@ -63,7 +63,7 @@ jobs: su `id -un 1000` -c 'git config --global user.email "github-actions[bot]@users.noreply.github.com"' - name: Setup Java ${{ matrix.java }} - uses: actions/setup-java@v4 + uses: actions/setup-java@c1e323688fd81a25caa38c78aa6df2d33d3e20d9 # v4 with: java-version: ${{ matrix.java }} distribution: 'temurin'