diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 226d3f6..f1eab77 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -15,7 +15,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 5 steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 with: persist-credentials: false @@ -37,7 +37,7 @@ jobs: matrix: rust: ["1.85", stable, beta] steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - name: Install Rust toolchain run: | @@ -77,7 +77,7 @@ jobs: --health-timeout 3s --health-retries 5 steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 with: # This job never pushes; don't leave the token in the git config # (zizmor: artipacked). @@ -127,7 +127,7 @@ jobs: --health-timeout 3s --health-retries 5 steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 with: # This job never pushes; don't leave the token in the git config # (zizmor: artipacked). @@ -168,7 +168,7 @@ jobs: # Public release-tarball checksum, not a credential. WASM_BINDGEN_SHA256: "3039f38f65fe237b640cf06a140c919ca8d717ec5012146d145d3f27bb4d6b28" # pragma: allowlist secret steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - name: Install Rust toolchain run: | diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index d49aace..2d37a23 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -84,7 +84,7 @@ jobs: # holds CARGO_REGISTRY_TOKEN and only runs on a release (a handful of # times a year), so a third-party action buys negligible build-time # savings against a real increase in that secret's trust surface. - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 with: # On dispatch, build and publish the tag's content — never main HEAD. # inputs.tag is empty on push events, so github.sha keeps the default diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 1a72c41..378b274 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -79,7 +79,7 @@ jobs: [ -x "$TOOL_ROOT/bin/cargo-audit" ] || cargo install cargo-audit --locked --version "$CARGO_AUDIT_VERSION" --root "$TOOL_ROOT" echo "$TOOL_ROOT/bin" >> "$GITHUB_PATH" - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 with: # This job never pushes; don't leave the token in the git config # (zizmor: artipacked).