diff --git a/.github/workflows/cd-dotnet.yml b/.github/workflows/cd-dotnet.yml index cac087c8..8922da92 100644 --- a/.github/workflows/cd-dotnet.yml +++ b/.github/workflows/cd-dotnet.yml @@ -38,12 +38,12 @@ jobs: runs-on: ubuntu-24.04 timeout-minutes: 30 steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Set up .NET - uses: actions/setup-dotnet@67a3573c9a986a3f9c594539f4ab511d57bb3ce9 # v4.3.1 + uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0 with: dotnet-version: '10.0.x' @@ -91,7 +91,7 @@ jobs: run: dotnet pack "$PACKAGE_PROJECT" --configuration Release --output artifacts ${PACK_ARGS:+"$PACK_ARGS"} - name: Upload package artifact - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: nuget-packages path: artifacts/*.nupkg diff --git a/.github/workflows/ci-c-coverage-combined.yml b/.github/workflows/ci-c-coverage-combined.yml index 378f1eda..23e3fd6b 100644 --- a/.github/workflows/ci-c-coverage-combined.yml +++ b/.github/workflows/ci-c-coverage-combined.yml @@ -92,7 +92,7 @@ jobs: # Check out main, then move to the target only if main contains it, so # nothing outside main is built. - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false ref: main @@ -230,7 +230,7 @@ jobs: - name: Upload combined coverage if: always() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: coverage-combined path: coverage-combined/ diff --git a/.github/workflows/ci-c-e2e-adu.yml b/.github/workflows/ci-c-e2e-adu.yml index 8aceaeb6..f621c1ee 100644 --- a/.github/workflows/ci-c-e2e-adu.yml +++ b/.github/workflows/ci-c-e2e-adu.yml @@ -65,7 +65,7 @@ jobs: AZ_IOT_E2E_SU_ARM_ENDPOINT: ${{ vars.E2E_SU_ARM_ENDPOINT }} SU_OFFERS_STATE: ${{ github.workspace }}/su-offers.json steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false @@ -100,7 +100,7 @@ jobs: } >> "$GITHUB_ENV" - name: Azure Login via OIDC - uses: azure/login@7184910d9eb2b1c5e48f7073824a90609bb9b6d6 # v2.3.1 + uses: azure/login@a641126d1b8aa4d1fa005f4f92df94a3a4c4c906 # v3.1.0 with: client-id: ${{ secrets.AZURE_CLIENT_ID }} tenant-id: ${{ secrets.AZURE_TENANT_ID }} @@ -138,7 +138,7 @@ jobs: - name: Upload test results if: always() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: e2e-su-results path: results/*.xml @@ -153,7 +153,7 @@ jobs: - name: Upload coverage tracefile if: success() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: coverage-trace-e2e-adu path: c/coverage/e2e-adu.json diff --git a/.github/workflows/ci-c-e2e-csr.yml b/.github/workflows/ci-c-e2e-csr.yml index 7eb2de5c..ac444dfb 100644 --- a/.github/workflows/ci-c-e2e-csr.yml +++ b/.github/workflows/ci-c-e2e-csr.yml @@ -122,12 +122,12 @@ jobs: # ADR namespace/policy, role assignments, and an ADR-integrated DPS. timeout-minutes: 60 steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Azure Login via OIDC - uses: azure/login@7184910d9eb2b1c5e48f7073824a90609bb9b6d6 # v2.3.1 + uses: azure/login@a641126d1b8aa4d1fa005f4f92df94a3a4c4c906 # v3.1.0 with: client-id: ${{ secrets.AZURE_CLIENT_ID }} tenant-id: ${{ secrets.AZURE_TENANT_ID }} @@ -160,7 +160,7 @@ jobs: dps-symmkey-group-enrollment-devices: '1' - name: Upload test config - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: e2e-csr-test-config path: test_config/set_test_env_vars.ps1 @@ -175,7 +175,7 @@ jobs: runs-on: ubuntu-24.04 timeout-minutes: 30 steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false @@ -192,7 +192,7 @@ jobs: - name: Download shared test config if: env.E2E_SHARED != 'true' - uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: e2e-csr-test-config path: test_config @@ -271,7 +271,7 @@ jobs: - name: Upload test results if: always() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: e2e-csr-results path: ./test_config/results/**/*.xml @@ -286,7 +286,7 @@ jobs: - name: Upload coverage tracefile if: success() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: coverage-trace-e2e-csr path: c/coverage/e2e-csr.json @@ -306,12 +306,12 @@ jobs: runs-on: ubuntu-24.04 timeout-minutes: 15 steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Azure Login via OIDC - uses: azure/login@7184910d9eb2b1c5e48f7073824a90609bb9b6d6 # v2.3.1 + uses: azure/login@a641126d1b8aa4d1fa005f4f92df94a3a4c4c906 # v3.1.0 with: client-id: ${{ secrets.AZURE_CLIENT_ID }} tenant-id: ${{ secrets.AZURE_TENANT_ID }} diff --git a/.github/workflows/ci-c-e2e.yml b/.github/workflows/ci-c-e2e.yml index 880d5c6f..fb75ebfe 100644 --- a/.github/workflows/ci-c-e2e.yml +++ b/.github/workflows/ci-c-e2e.yml @@ -107,12 +107,12 @@ jobs: runs-on: ubuntu-24.04 timeout-minutes: 30 steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Azure Login via OIDC - uses: azure/login@7184910d9eb2b1c5e48f7073824a90609bb9b6d6 # v2.3.1 + uses: azure/login@a641126d1b8aa4d1fa005f4f92df94a3a4c4c906 # v3.1.0 with: client-id: ${{ secrets.AZURE_CLIENT_ID }} tenant-id: ${{ secrets.AZURE_TENANT_ID }} @@ -142,7 +142,7 @@ jobs: enable-file-upload: 'true' - name: Upload test config - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: e2e-test-config path: test_config/set_test_env_vars.ps1 @@ -181,7 +181,7 @@ jobs: runs-on: ${{ matrix.os }} timeout-minutes: 30 steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false @@ -222,7 +222,7 @@ jobs: - name: Download shared test config if: env.E2E_SHARED != 'true' - uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: e2e-test-config path: test_config @@ -452,7 +452,7 @@ jobs: - name: Upload test results if: always() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: e2e-results-${{ matrix.os }} path: ./test_config/results/**/*.xml @@ -468,7 +468,7 @@ jobs: - name: Upload coverage tracefile (Linux) if: runner.os == 'Linux' && success() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: coverage-trace-e2e path: c/coverage/e2e.json @@ -488,12 +488,12 @@ jobs: runs-on: ubuntu-24.04 timeout-minutes: 15 steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Azure Login via OIDC - uses: azure/login@7184910d9eb2b1c5e48f7073824a90609bb9b6d6 # v2.3.1 + uses: azure/login@a641126d1b8aa4d1fa005f4f92df94a3a4c4c906 # v3.1.0 with: client-id: ${{ secrets.AZURE_CLIENT_ID }} tenant-id: ${{ secrets.AZURE_TENANT_ID }} diff --git a/.github/workflows/ci-c-static-analysis.yml b/.github/workflows/ci-c-static-analysis.yml index 71c33d5f..57756683 100644 --- a/.github/workflows/ci-c-static-analysis.yml +++ b/.github/workflows/ci-c-static-analysis.yml @@ -35,10 +35,10 @@ jobs: outputs: c: ${{ steps.filter.outputs.c == 'true' || steps.filter.outputs.common == 'true' || steps.filter.outputs.workflow == 'true' }} steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - - uses: dorny/paths-filter@0e4a8c6effa4802afeda77dc8d303f8176d7dfad # v3.0.4 + - uses: dorny/paths-filter@ceb8a2b8f2d89434be7ff52d3de7ec3738c5cc9d # v4.0.3 id: filter with: predicate-quantifier: every @@ -63,7 +63,7 @@ jobs: # (cert-err33-c.CheckedFunctions is this release's default list). CLANG_TIDY_VERSION: 18.1.8 steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false @@ -104,7 +104,7 @@ jobs: shell: bash working-directory: c steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - uses: ilammy/msvc-dev-cmd@0b201ec74fa43914dc39ae48a89fd1d8cb592756 # v1.13.0 diff --git a/.github/workflows/ci-c-yocto.yml b/.github/workflows/ci-c-yocto.yml index ac6722d9..4b48a44a 100644 --- a/.github/workflows/ci-c-yocto.yml +++ b/.github/workflows/ci-c-yocto.yml @@ -41,10 +41,10 @@ jobs: outputs: yocto: ${{ steps.filter.outputs.yocto }} steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - - uses: dorny/paths-filter@0e4a8c6effa4802afeda77dc8d303f8176d7dfad # v3.0.4 + - uses: dorny/paths-filter@ceb8a2b8f2d89434be7ff52d3de7ec3738c5cc9d # v4.0.3 id: filter with: # Only what the recipe builds: tests other than tests/install, @@ -71,7 +71,7 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false # bitbake clones this checkout; SRCREV must be reachable in it. @@ -89,7 +89,7 @@ jobs: } >> "$GITHUB_ENV" - name: Restore sstate - uses: actions/cache/restore@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0 + uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 with: path: ${{ runner.temp }}/yocto-sstate key: ${{ env.SSTATE_CACHE_PREFIX }}${{ github.run_id }}-${{ github.run_attempt }} @@ -176,7 +176,7 @@ jobs: # Also after a failure, cancellation or timeout: the next run continues. - name: Save sstate if: always() && steps.sstate.outputs.save == 'true' - uses: actions/cache/save@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0 + uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 with: path: ${{ runner.temp }}/yocto-sstate key: ${{ env.SSTATE_CACHE_PREFIX }}${{ github.run_id }}-${{ github.run_attempt }} diff --git a/.github/workflows/ci-c.yml b/.github/workflows/ci-c.yml index 539c98d7..54dd54bf 100644 --- a/.github/workflows/ci-c.yml +++ b/.github/workflows/ci-c.yml @@ -38,10 +38,10 @@ jobs: outputs: c: ${{ steps.filter.outputs.c == 'true' || steps.filter.outputs.common == 'true' || steps.filter.outputs.workflow == 'true' }} steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - - uses: dorny/paths-filter@0e4a8c6effa4802afeda77dc8d303f8176d7dfad # v3.0.4 + - uses: dorny/paths-filter@ceb8a2b8f2d89434be7ff52d3de7ec3738c5cc9d # v4.0.3 id: filter with: # `every`: a file counts only if it matches all patterns of a filter, @@ -102,7 +102,7 @@ jobs: --health-start-period=5s steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false @@ -150,7 +150,7 @@ jobs: if: needs.changes.outputs.c == 'true' || github.event_name != 'pull_request' runs-on: ubuntu-24.04 steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false # Guards the rules in c/docs/eng/coding-conventions.md. Cheap and @@ -213,7 +213,7 @@ jobs: --health-retries=10 --health-start-period=5s steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Install toolchain @@ -297,7 +297,7 @@ jobs: --health-retries=10 --health-start-period=5s steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Install deps @@ -330,7 +330,7 @@ jobs: fi - name: Upload valgrind logs if: always() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: valgrind-logs path: c/build/linux-gcc-debug/Testing/Temporary/MemoryChecker.*.log @@ -363,7 +363,7 @@ jobs: if: needs.changes.outputs.c == 'true' || github.event_name != 'pull_request' runs-on: ubuntu-24.04 steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Install deps @@ -412,7 +412,7 @@ jobs: exit "${status}" - name: Upload race-detector logs if: always() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: race-detector-logs path: c/build/linux-gcc-debug/*.log @@ -424,7 +424,7 @@ jobs: if: needs.changes.outputs.c == 'true' || github.event_name != 'pull_request' runs-on: windows-latest steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - uses: ilammy/msvc-dev-cmd@0b201ec74fa43914dc39ae48a89fd1d8cb592756 # v1.13.0 @@ -475,7 +475,7 @@ jobs: --health-retries=10 --health-start-period=5s steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Install deps @@ -523,7 +523,7 @@ jobs: matrix: mbedtls: [ '3.6.7', '4.1.1', '4.2.0' ] steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Install deps @@ -645,7 +645,7 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Install deps @@ -686,7 +686,7 @@ jobs: shell: bash working-directory: c steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - uses: ilammy/msvc-dev-cmd@0b201ec74fa43914dc39ae48a89fd1d8cb592756 # v1.13.0 @@ -752,7 +752,7 @@ jobs: shell: bash working-directory: c steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false @@ -966,7 +966,7 @@ jobs: --health-retries=10 --health-start-period=5s steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false # diff-cover compares against the merge base. @@ -1086,7 +1086,7 @@ jobs: run: bash eng/collect-coverage.sh build/linux-gcc-coverage coverage/unit.json unit-conformance - name: Upload coverage tracefile - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: coverage-trace-unit path: c/coverage/unit.json @@ -1134,7 +1134,7 @@ jobs: - name: Upload coverage report if: always() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: coverage-c path: c/build/linux-gcc-coverage/coverage/ diff --git a/.github/workflows/ci-dotnet.yml b/.github/workflows/ci-dotnet.yml index c85773e2..e18d54d6 100644 --- a/.github/workflows/ci-dotnet.yml +++ b/.github/workflows/ci-dotnet.yml @@ -48,12 +48,12 @@ jobs: runs-on: ubuntu-24.04 timeout-minutes: 30 steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Azure Login via OIDC - uses: azure/login@7184910d9eb2b1c5e48f7073824a90609bb9b6d6 # v2.3.1 + uses: azure/login@a641126d1b8aa4d1fa005f4f92df94a3a4c4c906 # v3.1.0 with: client-id: ${{ secrets.AZURE_CLIENT_ID }} tenant-id: ${{ secrets.AZURE_TENANT_ID }} @@ -76,7 +76,7 @@ jobs: dps-x509-individual-enrollments: '2' - name: Upload test config - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: e2e-test-config path: test_config/set_test_env_vars.ps1 @@ -97,7 +97,7 @@ jobs: runs-on: ${{ matrix.os }} timeout-minutes: 30 steps: - - uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false @@ -107,7 +107,7 @@ jobs: dotnet build ./Project.slnx - name: Download shared test config - uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: e2e-test-config path: test_config @@ -135,7 +135,7 @@ jobs: -- xunit.parallelizeAssembly=true - name: Upload Test Report Artifact - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: test-report-${{ matrix.os }} path: ./coverage/* @@ -169,7 +169,7 @@ jobs: contents: read steps: - name: Download Test Report Artifact - uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: test-report-${{ matrix.os }} path: ./coverage/ @@ -197,12 +197,12 @@ jobs: runs-on: ubuntu-24.04 timeout-minutes: 15 steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Azure Login via OIDC - uses: azure/login@7184910d9eb2b1c5e48f7073824a90609bb9b6d6 # v2.3.1 + uses: azure/login@a641126d1b8aa4d1fa005f4f92df94a3a4c4c906 # v3.1.0 with: client-id: ${{ secrets.AZURE_CLIENT_ID }} tenant-id: ${{ secrets.AZURE_TENANT_ID }} diff --git a/.github/workflows/cleanup-e2e-resources.yml b/.github/workflows/cleanup-e2e-resources.yml index c06f72de..f0fbdc53 100644 --- a/.github/workflows/cleanup-e2e-resources.yml +++ b/.github/workflows/cleanup-e2e-resources.yml @@ -54,7 +54,7 @@ jobs: steps: - name: Azure Login via OIDC - uses: azure/login@7184910d9eb2b1c5e48f7073824a90609bb9b6d6 # v2.3.1 + uses: azure/login@a641126d1b8aa4d1fa005f4f92df94a3a4c4c906 # v3.1.0 with: client-id: ${{ secrets.AZURE_CLIENT_ID }} tenant-id: ${{ secrets.AZURE_TENANT_ID }} @@ -63,7 +63,7 @@ jobs: # Checked out (rather than downloaded at run time) so the cleanup module # is always the commit this ref is pinned to. - name: Checkout the shared e2e framework - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5.1.0 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false repository: Azure/iot-sdks-e2e-fx diff --git a/.github/workflows/codeql-actions.yml b/.github/workflows/codeql-actions.yml index 3d4aa92b..3942b49d 100644 --- a/.github/workflows/codeql-actions.yml +++ b/.github/workflows/codeql-actions.yml @@ -29,7 +29,7 @@ jobs: contents: read security-events: write # Upload results to code scanning. steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false diff --git a/.github/workflows/codeql-c.yml b/.github/workflows/codeql-c.yml index baa27cc5..54997672 100644 --- a/.github/workflows/codeql-c.yml +++ b/.github/workflows/codeql-c.yml @@ -38,10 +38,10 @@ jobs: outputs: c: ${{ steps.filter.outputs.c == 'true' || steps.filter.outputs.common == 'true' || steps.filter.outputs.workflow == 'true' }} steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - - uses: dorny/paths-filter@0e4a8c6effa4802afeda77dc8d303f8176d7dfad # v3.0.4 + - uses: dorny/paths-filter@ceb8a2b8f2d89434be7ff52d3de7ec3738c5cc9d # v4.0.3 id: filter with: predicate-quantifier: every @@ -68,7 +68,7 @@ jobs: run: working-directory: c steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false diff --git a/.github/workflows/lint-workflows.yml b/.github/workflows/lint-workflows.yml index 279f0675..1ebdce53 100644 --- a/.github/workflows/lint-workflows.yml +++ b/.github/workflows/lint-workflows.yml @@ -29,7 +29,7 @@ jobs: ACTIONLINT_VERSION: 1.7.12 ACTIONLINT_SHA256: 8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8 steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Install actionlint @@ -48,7 +48,7 @@ jobs: runs-on: ubuntu-24.04 timeout-minutes: 10 steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - uses: zizmorcore/zizmor-action@cc914d7f3750a2d13d75c7f184a1060aa0e9d482 # v0.6.4