File tree Expand file tree Collapse file tree 4 files changed +7
-7
lines changed Expand file tree Collapse file tree 4 files changed +7
-7
lines changed Original file line number Diff line number Diff line change 5656
5757 # Initializes the CodeQL tools for scanning.
5858 - name : Initialize CodeQL
59- uses : github/codeql-action/init@v3
59+ uses : github/codeql-action/init@ff0a06e83cb2de871e5a09832bc6a81e7276941f # v3
6060 with :
6161 languages : ${{ matrix.language }}
6262 build-mode : none
7272 pip install -e .
7373
7474 - name : Perform CodeQL Analysis
75- uses : github/codeql-action/analyze@v3
75+ uses : github/codeql-action/analyze@ff0a06e83cb2de871e5a09832bc6a81e7276941f # v3
7676 with :
7777 category : " /language:${{ matrix.language }}"
Original file line number Diff line number Diff line change @@ -80,14 +80,14 @@ jobs:
8080 name : all-dist-${{ github.run_id }}
8181 path : dist/
8282 - name : Publish package distributions to TestPyPI
83- uses : pypa/gh-action-pypi-publish@release/v1
83+ uses : pypa/gh-action-pypi-publish@76f52bc884231f62b9a034ebfe128415bbaabdfc # release/v1
8484 with :
8585 repository-url : https://test.pypi.org/legacy/
8686 skip-existing : true
8787 attestations : ${{ env.DRY_RUN }}
8888 - name : Publish package distributions to PyPI
8989 if : startsWith(env.DRY_RUN, 'false')
90- uses : pypa/gh-action-pypi-publish@release/v1
90+ uses : pypa/gh-action-pypi-publish@76f52bc884231f62b9a034ebfe128415bbaabdfc # release/v1
9191
9292 post-publish :
9393 needs : [publish]
Original file line number Diff line number Diff line change 5050 - name : Copy the test runner file
5151 run : cp .github/workflows/runtests.py django_repo/tests/runtests_.py
5252 - name : Start MongoDB
53- uses : supercharge/mongodb-github-action@1.12.0
53+ uses : supercharge/mongodb-github-action@90004df786821b6308fb02299e5835d0dae05d0d # 1.12.0
5454 with :
5555 mongodb-version : 6.0
5656 - name : Run tests
Original file line number Diff line number Diff line change @@ -18,15 +18,15 @@ jobs:
1818 with :
1919 persist-credentials : false
2020 - name : Setup Rust
21- uses : actions-rust-lang/setup-rust-toolchain@v1
21+ uses : actions-rust-lang/setup-rust-toolchain@9d7e65c320fdb52dcd45ffaa68deb6c02c8754d9 # v1
2222 - name : Get zizmor
2323 run : cargo install zizmor
2424 - name : Run zizmor
2525 run : zizmor --format sarif . > results.sarif
2626 env :
2727 GH_TOKEN : ${{ secrets.GITHUB_TOKEN }}
2828 - name : Upload SARIF file
29- uses : github/codeql-action/upload-sarif@v3
29+ uses : github/codeql-action/upload-sarif@ff0a06e83cb2de871e5a09832bc6a81e7276941f # v3
3030 with :
3131 sarif_file : results.sarif
3232 category : zizmor
You can’t perform that action at this time.
0 commit comments