Skip to content

Commit a99eb52

Browse files
authored
Merge pull request #51 from intility/pipeline
Improve pipeline security posture
2 parents 77c4f8d + 4ea5174 commit a99eb52

File tree

2 files changed

+13
-4
lines changed

2 files changed

+13
-4
lines changed

.github/dependabot.yaml

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
version: 2
2+
3+
updates:
4+
- package-ecosystem: github-actions
5+
directory: /
6+
commit-message:
7+
prefix: "deps:"
8+
schedule:
9+
interval: weekly

.github/workflows/go.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -15,10 +15,10 @@ jobs:
1515
build-test-release:
1616
runs-on: ubuntu-latest
1717
steps:
18-
- uses: actions/checkout@v4
18+
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
1919

2020
- name: Set up Go
21-
uses: actions/setup-go@v4
21+
uses: actions/setup-go@19bb51245e9c80abacb2e91cc42b33fa478b8639 # v4.2.1
2222
with:
2323
go-version: "1.24.2"
2424

@@ -30,15 +30,15 @@ jobs:
3030

3131
- name: Generate GitHub app token for Homebrew Tap App
3232
id: generate-app-token
33-
uses: actions/create-github-app-token@v1
33+
uses: actions/create-github-app-token@d72941d797fd3113feb6b93fd0dec494b13a2547 # v1.12.0
3434
with:
3535
app-id: ${{ vars.HOMEBREW_TAP_APP_ID }}
3636
private-key: ${{ secrets.HOMEBREW_TAP_APP_PRIVATE_KEY }}
3737
owner: intility
3838
repositories: homebrew-tap
3939

4040
- name: GoReleaser Action
41-
uses: goreleaser/goreleaser-action@v5.1.0
41+
uses: goreleaser/goreleaser-action@5742e2a039330cbb23ebf35f046f814d4c6ff811 # v5.1.0
4242
with:
4343
args: release --clean
4444
version: 2

0 commit comments

Comments
 (0)