diff --git a/.github/workflows/nix-flake-check.yaml b/.github/workflows/nix-flake-check.yaml index b0d951a..c22c62e 100644 --- a/.github/workflows/nix-flake-check.yaml +++ b/.github/workflows/nix-flake-check.yaml @@ -14,7 +14,7 @@ jobs: contents: read steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - - uses: determinatesystems/nix-installer-action@c5a866b6ab867e88becbed4467b93592bce69f8a # v21 + - uses: determinatesystems/nix-installer-action@ef8a148080ab6020fd15196c2084a2eea5ff2d25 # v22 - run: | echo "Version: \`$(nix --version)\`" \ | tee --append "${GITHUB_STEP_SUMMARY}" diff --git a/.github/workflows/run-pre-commit-via-determinate.yaml b/.github/workflows/run-pre-commit-via-determinate.yaml index 3b34b36..2dccf60 100644 --- a/.github/workflows/run-pre-commit-via-determinate.yaml +++ b/.github/workflows/run-pre-commit-via-determinate.yaml @@ -25,7 +25,7 @@ jobs: with: fetch-depth: 0 - - uses: determinatesystems/nix-installer-action@c5a866b6ab867e88becbed4467b93592bce69f8a # v21 + - uses: determinatesystems/nix-installer-action@ef8a148080ab6020fd15196c2084a2eea5ff2d25 # v22 - uses: determinatesystems/magic-nix-cache-action@565684385bcd71bad329742eefe8d12f2e765b39 # v13 - uses: determinatesystems/flake-checker-action@3164002371bc90729c68af0e24d5aacf20d7c9f6 # v12 diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 3e63b98..d47f052 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -66,7 +66,7 @@ jobs: # Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF # format to the repository Actions tab. - name: "Upload Artifact" - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6.0.0 + uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0 with: name: SARIF file path: results.sarif @@ -75,6 +75,6 @@ jobs: # Upload the results to GitHub's code scanning dashboard (optional). # Commenting out will disable upload of results to your repo's Code Scanning dashboard - name: "Upload SARIF" - uses: github/codeql-action/upload-sarif@6bc82e05fd0ea64601dd4b465378bbcf57de0314 # v4.32.1 + uses: github/codeql-action/upload-sarif@c10b8064de6f491fea524254123dbe5e09572f13 # v4.35.1 with: sarif_file: results.sarif diff --git a/.github/workflows/update-flake-lock.yml b/.github/workflows/update-flake-lock.yml index 6730366..ef2a7c4 100644 --- a/.github/workflows/update-flake-lock.yml +++ b/.github/workflows/update-flake-lock.yml @@ -17,7 +17,7 @@ jobs: pull-requests: write runs-on: ubuntu-latest steps: - - uses: actions/create-github-app-token@29824e69f54612133e76f7eaac726eef6c875baf # v2.2.1 + - uses: actions/create-github-app-token@f8d387b68d61c58ab83c6c016672934102569859 # v3.0.0 id: create-token with: app-id: ${{ vars.APP_ID }} @@ -27,7 +27,7 @@ jobs: with: token: ${{ steps.create-token.outputs.token }} - - uses: determinatesystems/determinate-nix-action@89ab342bd48ff7318caf8d39d6a330c7b1df8f2f # v3.15.2 + - uses: determinatesystems/determinate-nix-action@a18f73c54ca8525de051e73c31512a67f44df919 # v3.17.1 # References: # dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>