Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/proto.yml
Original file line number Diff line number Diff line change
Expand Up @@ -83,7 +83,7 @@ jobs:
# setup action — install a pinned buf on PATH — so the explicit `buf`
# invocations below stay readable and match the Makefile targets.
- name: Set up buf
uses: bufbuild/buf-action@8c6a16e16f12ba20b6470afa9c2ba9b5ba8c97c3 # v1.5.0
uses: bufbuild/buf-action@85aebf73123b5c15fd5528aaecbf9129cddf7fa7 # v1.6.0
with:
version: ${{ env.BUF_VERSION }}
setup_only: true
Expand All @@ -110,7 +110,7 @@ jobs:
fetch-depth: 0

- name: Set up buf
uses: bufbuild/buf-action@8c6a16e16f12ba20b6470afa9c2ba9b5ba8c97c3 # v1.5.0
uses: bufbuild/buf-action@85aebf73123b5c15fd5528aaecbf9129cddf7fa7 # v1.6.0
with:
version: ${{ env.BUF_VERSION }}
setup_only: true
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/security.yml
Original file line number Diff line number Diff line change
Expand Up @@ -211,7 +211,7 @@ jobs:
# Buildx gives us the modern BuildKit builder (cache mounts in the
# Dockerfile, multi-stage, provenance) used by build-push-action.
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1

# Derive tags/labels from git context. On a PR we build but do NOT push
# (no login below); on push/tag we push and sign. metadata-action emits a
Expand All @@ -232,7 +232,7 @@ jobs:
# keeps PR runs read-only and avoids a useless auth attempt.
- name: Log in to GHCR
if: github.event_name == 'push'
uses: docker/login-action@abd2ef45e78c5afb21d64d4ca52ee8550d9572c7 # v4.5.1
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
Expand All @@ -249,7 +249,7 @@ jobs:
# so the signature is immutable even if the tag is later re-pointed).
- name: Build image
id: build
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
context: .
file: services/${{ matrix.service }}/Dockerfile
Expand Down Expand Up @@ -301,7 +301,7 @@ jobs:
# Syft; CycloneDX is the format policy engines + `cosign attest` consume.
# Uploaded as an artifact (and as a release asset on a tag).
- name: Generate CycloneDX SBOM (Syft)
uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0
uses: anchore/sbom-action@3ad7283483fc7af8ff2b4ea19663c2d5ca935e26 # v0.24.2
with:
image: ${{ steps.target.outputs.image }}
format: cyclonedx-json
Expand Down
Loading