Browse Source

Merge 2a7785bd09 into 06994656fe

pull/512/merge
renovate[bot] 2 days ago committed by GitHub
parent
commit
faf84b1420
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
  1. 2
      .github/templates/workflow-templates/example-references/_build.yml
  2. 2
      .github/templates/workflow-templates/example-references/_docker.yml
  3. 2
      .github/templates/workflow-templates/example-references/_test.yml
  4. 2
      .github/templates/workflow-templates/example-references/_version.yml
  5. 2
      .github/templates/workflow-templates/example.yaml
  6. 2
      .github/workflows/_checkmarx.yml
  7. 4
      .github/workflows/_ephemeral_environment_manager.yml
  8. 2
      .github/workflows/_publish-mobile-github-release.yml
  9. 2
      .github/workflows/_sonar.yml
  10. 2
      .github/workflows/_version.yml
  11. 18
      .github/workflows/test-download-artifacts.yml
  12. 4
      .github/workflows/test-get-secrets.yml
  13. 2
      .github/workflows/test-release-version-check.yml
  14. 4
      .github/workflows/test-report-deployment-status-to-slack.yml
  15. 2
      .github/workflows/test-report-upcoming-release-version.yml
  16. 2
      .github/workflows/test-version-bump.yml
  17. 2
      .github/workflows/test-version-check.yml
  18. 2
      .github/workflows/workflow-linter.yml

2
.github/templates/workflow-templates/example-references/_build.yml

@ -20,7 +20,7 @@ jobs: @@ -20,7 +20,7 @@ jobs:
runs-on: ubuntu-22.04
steps:
- name: Check out repository
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
fetch-depth: 0

2
.github/templates/workflow-templates/example-references/_docker.yml

@ -27,7 +27,7 @@ jobs: @@ -27,7 +27,7 @@ jobs:
runs-on: ubuntu-22.04
steps:
- name: Check out repository
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
fetch-depth: 0

2
.github/templates/workflow-templates/example-references/_test.yml

@ -22,7 +22,7 @@ jobs: @@ -22,7 +22,7 @@ jobs:
steps:
- name: Check out repo
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
fetch-depth: 0

2
.github/templates/workflow-templates/example-references/_version.yml

@ -20,7 +20,7 @@ jobs: @@ -20,7 +20,7 @@ jobs:
version: ${{ steps.version.outputs.value }}
steps:
- name: Check out repository
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
fetch-depth: 0

2
.github/templates/workflow-templates/example.yaml

@ -92,7 +92,7 @@ jobs: # A workflow run is made up of one or more jobs that can run sequentially @@ -92,7 +92,7 @@ jobs: # A workflow run is made up of one or more jobs that can run sequentially
# NOT RECOMMENDED if: always() # run even if previous steps failed or the workflow is canceled, this can cause a workflow run to hang indefinitely
if: failure() # run when any previous step of a job fails
# if: '!cancelled()' # run even if previous steps failed
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 Always pin a public action version to a full git SHA, followed by the version number in a comment. Version pins are insecure and can introduce vulnerabilities into workflows.
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1 Always pin a public action version to a full git SHA, followed by the version number in a comment. Version pins are insecure and can introduce vulnerabilities into workflows.
with: # Parameters specific to this action that need to be defined in order for the step to be completed
fetch-depth: 0 # Full git history for actions that rely on whether a change has occurred
ref: ${{ github.event.pull_request.head.sha }}

2
.github/workflows/_checkmarx.yml

@ -37,7 +37,7 @@ jobs: @@ -37,7 +37,7 @@ jobs:
steps:
- name: Check out repo
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
ref: ${{ github.event.pull_request.head.sha }}
persist-credentials: false

4
.github/workflows/_ephemeral_environment_manager.yml

@ -67,7 +67,7 @@ jobs: @@ -67,7 +67,7 @@ jobs:
uses: bitwarden/gh-actions/azure-logout@main
- name: Checkout Ephemeral Environment Charts
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
repository: bitwarden/ephemeral-environment-charts
token: "${{ steps.retrieve-secrets.outputs.github-pat-bitwarden-devops-bot-repo-scope }}"
@ -109,7 +109,7 @@ jobs: @@ -109,7 +109,7 @@ jobs:
uses: bitwarden/gh-actions/azure-logout@main
- name: Checkout ${{ inputs.project }}
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
repository: bitwarden/${{ inputs.project }}
ref: ${{ inputs.ephemeral_env_branch }}

2
.github/workflows/_publish-mobile-github-release.yml

@ -46,7 +46,7 @@ jobs: @@ -46,7 +46,7 @@ jobs:
steps:
- name: Check out repository
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
fetch-depth: 0
persist-credentials: false

2
.github/workflows/_sonar.yml

@ -40,7 +40,7 @@ jobs: @@ -40,7 +40,7 @@ jobs:
steps:
- name: Check out repo
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
fetch-depth: 0
ref: ${{ github.event.pull_request.head.sha }}

2
.github/workflows/_version.yml

@ -25,7 +25,7 @@ jobs: @@ -25,7 +25,7 @@ jobs:
version: ${{ steps.calculate.outputs.version }}
steps:
- name: Checkout Repo
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
fetch-depth: 0
persist-credentials: false

18
.github/workflows/test-download-artifacts.yml

@ -22,7 +22,7 @@ jobs: @@ -22,7 +22,7 @@ jobs:
runs-on: ubuntu-22.04
steps:
- name: Checkout
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
persist-credentials: false
@ -44,7 +44,7 @@ jobs: @@ -44,7 +44,7 @@ jobs:
if: github.ref == 'refs/heads/main'
steps:
- name: Checkout
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
persist-credentials: false
@ -67,7 +67,7 @@ jobs: @@ -67,7 +67,7 @@ jobs:
if: github.event_name != 'pull_request'
steps:
- name: Checkout
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
persist-credentials: false
@ -99,7 +99,7 @@ jobs: @@ -99,7 +99,7 @@ jobs:
if: github.event_name == 'pull_request'
steps:
- name: Checkout
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
persist-credentials: false
@ -121,7 +121,7 @@ jobs: @@ -121,7 +121,7 @@ jobs:
runs-on: ubuntu-22.04
steps:
- name: Checkout
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
persist-credentials: false
@ -142,7 +142,7 @@ jobs: @@ -142,7 +142,7 @@ jobs:
runs-on: ubuntu-22.04
steps:
- name: Checkout
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
persist-credentials: false
@ -164,7 +164,7 @@ jobs: @@ -164,7 +164,7 @@ jobs:
runs-on: ubuntu-22.04
steps:
- name: Checkout
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
persist-credentials: false
@ -185,7 +185,7 @@ jobs: @@ -185,7 +185,7 @@ jobs:
runs-on: ubuntu-22.04
steps:
- name: Checkout
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
persist-credentials: false
@ -207,7 +207,7 @@ jobs: @@ -207,7 +207,7 @@ jobs:
runs-on: ubuntu-22.04
steps:
- name: Checkout
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
persist-credentials: false

4
.github/workflows/test-get-secrets.yml

@ -28,7 +28,7 @@ jobs: @@ -28,7 +28,7 @@ jobs:
id-token: write
steps:
- name: Check out repo
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
fetch-depth: 0
persist-credentials: false
@ -130,7 +130,7 @@ jobs: @@ -130,7 +130,7 @@ jobs:
id-token: write
steps:
- name: Check out repo
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
fetch-depth: 0
persist-credentials: false

2
.github/workflows/test-release-version-check.yml

@ -64,7 +64,7 @@ jobs: @@ -64,7 +64,7 @@ jobs:
xamarin_calver_fail_status: ${{ steps.set-status.outputs.xamarin_calver_fail }}
steps:
- name: Checkout Branch
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
persist-credentials: false

4
.github/workflows/test-report-deployment-status-to-slack.yml

@ -18,7 +18,7 @@ jobs: @@ -18,7 +18,7 @@ jobs:
id-token: write
steps:
- name: Checkout
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
persist-credentials: false
@ -86,7 +86,7 @@ jobs: @@ -86,7 +86,7 @@ jobs:
id-token: write
steps:
- name: Checkout
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
persist-credentials: false

2
.github/workflows/test-report-upcoming-release-version.yml

@ -14,7 +14,7 @@ jobs: @@ -14,7 +14,7 @@ jobs:
id-token: write
steps:
- name: Checkout
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
persist-credentials: false

2
.github/workflows/test-version-bump.yml

@ -23,7 +23,7 @@ jobs: @@ -23,7 +23,7 @@ jobs:
runs-on: ubuntu-22.04
steps:
- name: Checkout
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
persist-credentials: false

2
.github/workflows/test-version-check.yml

@ -79,7 +79,7 @@ jobs: @@ -79,7 +79,7 @@ jobs:
should-fail: true
steps:
- name: Check out repo
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
fetch-depth: 0
persist-credentials: false

2
.github/workflows/workflow-linter.yml

@ -18,7 +18,7 @@ jobs: @@ -18,7 +18,7 @@ jobs:
runs-on: ubuntu-24.04
steps:
- name: Check out branch
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
repository: ${{ github.repository }}
fetch-depth: ${{ github.event_name == 'pull_request' && 2 || 0 }}

Loading…
Cancel
Save