From e21ff3e011a3dd2724b52341adb69d401b7ec8ac Mon Sep 17 00:00:00 2001 From: Pauline Bailly-Masson <155966238+paulinebm@users.noreply.github.com> Date: Thu, 2 Apr 2026 11:25:35 +0200 Subject: [PATCH 1/3] =?UTF-8?q?=F0=9F=94=92=20pin=20python-api-diffusers-c?= =?UTF-8?q?d.yaml=20actions=20to=20commit=20SHAs?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .github/workflows/python-api-diffusers-cd.yaml | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/.github/workflows/python-api-diffusers-cd.yaml b/.github/workflows/python-api-diffusers-cd.yaml index 844b3169..aed17c1b 100644 --- a/.github/workflows/python-api-diffusers-cd.yaml +++ b/.github/workflows/python-api-diffusers-cd.yaml @@ -17,28 +17,28 @@ jobs: contents: read steps: - name: Checkout - uses: actions/checkout@v4.1.7 + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - name: Inject slug/short variables - uses: rlespinasse/github-slug-action@v4.5.0 + uses: rlespinasse/github-slug-action@797d68864753cbceedc271349d402da4590e6302 # v4.5.0 - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v3.6.1 + uses: docker/setup-buildx-action@988b5a0280414f521da01fcc63a27aeeb4b104db # v3.6.1 - name: downcase REPO run: | echo "CONTAINER_REPO=${GITHUB_REPOSITORY,,}" >>${GITHUB_ENV} - name: Docker meta id: meta - uses: docker/metadata-action@v5.5.1 + uses: docker/metadata-action@8e5442c4ef9f78752691e2d8f8d19755c6f78e81 # v5.5.1 with: images: ghcr.io/${{ env.CONTAINER_REPO }} - name: Login to GitHub Container Registry - uses: docker/login-action@v3.3.0 + uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Build and push Docker image id: build-and-push - uses: docker/build-push-action@v6.5.0 + uses: docker/build-push-action@5176d81f87c23d6fc96624dfdbcd9f3830bbe445 # v6.5.0 with: context: docker_images/diffusers push: true From 7382433abbc1a4b2c85c7e9f41a400e958c29cfa Mon Sep 17 00:00:00 2001 From: Pauline Bailly-Masson <155966238+paulinebm@users.noreply.github.com> Date: Thu, 2 Apr 2026 11:25:36 +0200 Subject: [PATCH 2/3] =?UTF-8?q?=F0=9F=94=92=20pin=20python-api-mindspore-c?= =?UTF-8?q?d.yaml=20actions=20to=20commit=20SHAs?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .github/workflows/python-api-mindspore-cd.yaml | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/.github/workflows/python-api-mindspore-cd.yaml b/.github/workflows/python-api-mindspore-cd.yaml index 2718685a..b895a343 100644 --- a/.github/workflows/python-api-mindspore-cd.yaml +++ b/.github/workflows/python-api-mindspore-cd.yaml @@ -10,20 +10,20 @@ jobs: runs-on: ubuntu-latest steps: - name: Set up Python ${{ matrix.python-version }} - uses: actions/setup-python@v4 + uses: actions/setup-python@7f4fc3e22c37d6ff65e88745f38bd3157c663f7c # v4 with: python-version: "3.10" - name: Checkout - uses: actions/checkout@v2 + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - name: Set up QEMU - uses: docker/setup-qemu-action@v1 + uses: docker/setup-qemu-action@27d0a4f181a40b142cce983c5393082c365d1480 # v1 - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v1 + uses: docker/setup-buildx-action@f211e3e9ded2d9377c8cadc4489a4e38014bc4c9 # v1 - name: Install dependencies run: | pip install --upgrade pip pip install awscli - - uses: huggingface/tailscale-action@v1 + - uses: huggingface/tailscale-action@ee9ee9c497b1088140a77088ee948ed0bc91f9d0 # v1 with: authkey: ${{ secrets.TAILSCALE_AUTHKEY }} - name: Update upstream From 2f7da66383bec252953d9cec5d7fa3b9852741dd Mon Sep 17 00:00:00 2001 From: Pauline Bailly-Masson <155966238+paulinebm@users.noreply.github.com> Date: Thu, 2 Apr 2026 11:25:37 +0200 Subject: [PATCH 3/3] =?UTF-8?q?=F0=9F=94=92=20pin=20python-api-adapter-tra?= =?UTF-8?q?nsformers.yaml=20actions=20to=20commit=20SHAs?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .github/workflows/python-api-adapter-transformers.yaml | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/python-api-adapter-transformers.yaml b/.github/workflows/python-api-adapter-transformers.yaml index 5d191a6d..be98c7b8 100644 --- a/.github/workflows/python-api-adapter-transformers.yaml +++ b/.github/workflows/python-api-adapter-transformers.yaml @@ -9,15 +9,15 @@ jobs: runs-on: ubuntu-latest steps: - name: Set up Python ${{ matrix.python-version }} - uses: actions/setup-python@v2 + uses: actions/setup-python@e9aba2c848f5ebd159c070c61ea2c4e2b122355e # v2 with: python-version: "3.8" - name: Checkout - uses: actions/checkout@v2 + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - name: Set up QEMU - uses: docker/setup-qemu-action@v1 + uses: docker/setup-qemu-action@27d0a4f181a40b142cce983c5393082c365d1480 # v1 - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v1 + uses: docker/setup-buildx-action@f211e3e9ded2d9377c8cadc4489a4e38014bc4c9 # v1 - name: Install dependencies run: | pip install --upgrade pip