Summary
Update the GitHub Actions used in this repository, and pin them to commit hashes.
The go.yml and release.yml workflows are rather specialised for this repository, however at some point in the near future, it would be nice to move some of these workflows to https://github.com/hemilabs/actions.
Changes
Pin actions/cache to v4.1.2 (6849a6489940f00c2f30c0fb92c6274307ccb58a)
Pin actions/checkout to v4.2.2 (11bd71901bbe5b1630ceea73d27597364c9af683)
Pin actions/labeler to v5.0.0 (8558fd74291d67161a8a78ce36a881fa63b766a9)
Pin actions/setup-go to v5.1.0 (41dfa10bad2bb2ae585af6ee5bb4d7d973ad74ed)
Pin actions/setup-node to v4.1.0 (39370e3970a6d050c480ffad4ff0ed4d3fdee5af)
Pin docker/login-action to v3.3.0 (9780b0c442fbb1117ed29e0efdff1e18412f7567)
Pin docker/setup-buildx-action to v3.7.1 (c47758b77c9736f4b2ef4073d4d51994fabfe349)
Pin docker/setup-qemu-action to v3.2.0 (49b3bc8e6bdd4a60e6116a5414239cba5943d3cf)
Pin goreleaser/goreleaser-action to v6.0.0 (286f3b13b1b49da4ac219696163fb8c1c93e1200)
Pin pnpm/action-setup to v4.0.0 (0c17529a66aca453f9227af23103ed11469b1e47)
Update and pin anchore/sbom-action/download-syft to v0.17.5 (1ca97d9028b51809cf6d3c934c3e160716e1b605) (from v0.17.0)
Update and pin sigstore/cosign-installer to v3.7.0 (1aa8e0f2454b781fbf0fbf306a4c9533a0c57409) (from v3.6.0)
Summary Update the GitHub Actions used in this repository, and pin them to commit hashes.
The
go.yml
andrelease.yml
workflows are rather specialised for this repository, however at some point in the near future, it would be nice to move some of these workflows to https://github.com/hemilabs/actions.Changes
actions/cache
to v4.1.2 (6849a6489940f00c2f30c0fb92c6274307ccb58a
)actions/checkout
to v4.2.2 (11bd71901bbe5b1630ceea73d27597364c9af683
)actions/labeler
to v5.0.0 (8558fd74291d67161a8a78ce36a881fa63b766a9
)actions/setup-go
to v5.1.0 (41dfa10bad2bb2ae585af6ee5bb4d7d973ad74ed
)actions/setup-node
to v4.1.0 (39370e3970a6d050c480ffad4ff0ed4d3fdee5af
)docker/login-action
to v3.3.0 (9780b0c442fbb1117ed29e0efdff1e18412f7567
)docker/setup-buildx-action
to v3.7.1 (c47758b77c9736f4b2ef4073d4d51994fabfe349
)docker/setup-qemu-action
to v3.2.0 (49b3bc8e6bdd4a60e6116a5414239cba5943d3cf
)goreleaser/goreleaser-action
to v6.0.0 (286f3b13b1b49da4ac219696163fb8c1c93e1200
)pnpm/action-setup
to v4.0.0 (0c17529a66aca453f9227af23103ed11469b1e47
)anchore/sbom-action/download-syft
to v0.17.5 (1ca97d9028b51809cf6d3c934c3e160716e1b605
) (from v0.17.0)sigstore/cosign-installer
to v3.7.0 (1aa8e0f2454b781fbf0fbf306a4c9533a0c57409
) (from v3.6.0)