Skip to content

Commit

Permalink
[CP-Sec] Revert hash pinning for GitHub actions
Browse files Browse the repository at this point in the history
  • Loading branch information
carlewis committed Oct 3, 2024
1 parent 8368515 commit 2fd0a22
Show file tree
Hide file tree
Showing 11 changed files with 33 additions and 33 deletions.
2 changes: 1 addition & 1 deletion .github/actions/build_portBLAS_action/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ runs:
tar -cvzf portBLAS_build.tar.gz portBLAS_build_dir
- name: Upload Artifacts
uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # v4.4.0
uses: actions/upload-artifact@v4
with:
name: portBLAS_build
path: portBLAS_build.tar.gz
2 changes: 1 addition & 1 deletion .github/actions/build_portDNN_action/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -47,7 +47,7 @@ runs:
tar -cvzf portDNN_build.tar.gz portDNN_build_dir
- name: Upload Artifacts
uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # v4.4.0
uses: actions/upload-artifact@v4
with:
name: portDNN_build
path: portDNN_build.tar.gz
4 changes: 2 additions & 2 deletions .github/actions/build_vgg_resnet_action/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ runs:
using: "composite"
steps:
- name: setup python
uses: actions/setup-python@f677139bbe7f9c59b41e40162b753c062f5d49a3 # v5.2.0
uses: actions/setup-python@v5
with:
python-version: '3.8'

Expand Down Expand Up @@ -88,7 +88,7 @@ runs:
tar -cvzf network_artifacts.tar.gz vgg_data resnet_data Labrador_Retriever_Molly.jpg Labrador_Retriever_Molly.jpg.bin
- name: Upload Artifacts
uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # v4.4.0
uses: actions/upload-artifact@v4
with:
name: network_build
path: network_artifacts.tar.gz
2 changes: 1 addition & 1 deletion .github/actions/setup_ubuntu_build/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@ runs:
uses: llvm/actions/install-ninja@main

- name: load llvm
uses: actions/cache/restore@0c45773b623bea8c8e75f6c82b208c3cf94ea4f9 # v4.0.2
uses: actions/cache/restore@v4
with:
path: llvm_install/**
key: llvm-ubuntu-${{ inputs.ubuntu_version }}-${{ inputs.arch }}-v${{ inputs.llvm_version}}-${{ inputs.llvm_build_type }}
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/build_pr_cache.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ jobs:

steps:
- name: Checkout repo
uses: actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 # v4.2.0
uses: actions/checkout@v4

# installs tools, ninja and installs llvm (default 17, RelAssert) and sets up cache
- name: setup-ubuntu
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/create_llvm.yml
Original file line number Diff line number Diff line change
Expand Up @@ -54,7 +54,7 @@ jobs:
steps:
- name: Cache llvm
id: cache
uses: actions/cache@0c45773b623bea8c8e75f6c82b208c3cf94ea4f9 # v4.0.2
uses: actions/cache@v4
with:
path:
llvm_install/**
Expand All @@ -68,14 +68,14 @@ jobs:

- name: Checkout repo llvm
if: steps.cache.outputs.cache-hit != 'true'
uses: actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 # v4.2.0
uses: actions/checkout@v4
with:
repository: llvm/llvm-project
ref: release/${{matrix.version}}.x

- name: Checkout repo ock platform
if: ${{ steps.cache.outputs.cache-hit != 'true' && matrix.arch != 'x86_64' }}
uses: actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 # v4.2.0
uses: actions/checkout@v4
with:
sparse-checkout: |
platform
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/create_publish_artifacts.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ jobs:

steps:
- name: Checkout repo
uses: actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 # v4.2.0
uses: actions/checkout@v4

# installs tools, ninja, installs llvm and sets up sccache
- name: Setup ubuntu
Expand All @@ -32,7 +32,7 @@ jobs:
llvm_build_type: Release

- name: Setup python
uses: actions/setup-python@f677139bbe7f9c59b41e40162b753c062f5d49a3 # v5.2.0
uses: actions/setup-python@v5
with:
python-version: '3.8'

Expand Down Expand Up @@ -85,7 +85,7 @@ jobs:
tar -czf ock_install.tar.gz install
- name: Upload Artifacts
uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # v4.4.0
uses: actions/upload-artifact@v4
with:
name: riscv-build
path: ock_install.tar.gz
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/docs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,9 +23,9 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 # v4.2.0
uses: actions/checkout@v4

- uses: actions/setup-python@f677139bbe7f9c59b41e40162b753c062f5d49a3 # v5.2.0
- uses: actions/setup-python@v5
with:
python-version: 3.9

Expand All @@ -44,6 +44,6 @@ jobs:
cmake --build build_doc --target doc_html
- name: Upload artifact
uses: actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa # v3.0.1
uses: actions/upload-pages-artifact@v3
with:
path: ${{github.workspace}}/build_doc/doc/html
28 changes: 14 additions & 14 deletions .github/workflows/run_ock_demo.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ jobs:

steps:
- name: Checkout repo
uses: actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 # v4.2.0
uses: actions/checkout@v4

# installs tools, ninja, installs llvm and sets up sccahe
- name: setup ubuntu
Expand All @@ -31,7 +31,7 @@ jobs:
llvm_build_type: RelAssert

- name: setup python
uses: actions/setup-python@f677139bbe7f9c59b41e40162b753c062f5d49a3 # v5.2.0
uses: actions/setup-python@v5
with:
python-version: '3.8'

Expand Down Expand Up @@ -91,7 +91,7 @@ jobs:
tar -cvzf ock_demo_artifacts.tar.gz ock_install_dir -C examples/technical_blogs/ock_demo_blog getting_started.md envvars
- name: Upload OCK artifacts
uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # v4.4.0
uses: actions/upload-artifact@v4
with:
name: ock_demo_build
path: ock_demo_artifacts.tar.gz
Expand All @@ -101,10 +101,10 @@ jobs:
needs: run_riscv_m1_ock_demo
steps:
- name: Checkout repo
uses: actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 # v4.2.0
uses: actions/checkout@v4

- name: Download OCK artifacts
uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # 4.1.8
uses: actions/download-artifact@v4
with:
name: ock_demo_build

Expand All @@ -122,10 +122,10 @@ jobs:
needs: run_riscv_m1_ock_demo
steps:
- name: Checkout repo
uses: actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 # v4.2.0
uses: actions/checkout@v4

- name: Download OCK artifacts
uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # 4.1.8
uses: actions/download-artifact@v4
with:
name: ock_demo_build

Expand All @@ -145,15 +145,15 @@ jobs:
needs: [run_riscv_m1_ock_demo, build_portDNN]
steps:
- name: Checkout repo
uses: actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 # v4.2.0
uses: actions/checkout@v4

- name: Download OCK artifacts
uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # 4.1.8
uses: actions/download-artifact@v4
with:
name: ock_demo_build

- name: Download portDNN build artifacts
uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # 4.1.8
uses: actions/download-artifact@v4
with:
name: portDNN_build

Expand All @@ -174,22 +174,22 @@ jobs:
GH_TOKEN: ${{ secrets.GH_TOKEN }}
steps:
- name: Download OCK artifacts
uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # 4.1.8
uses: actions/download-artifact@v4
with:
name: ock_demo_build

- name: Download portDNN build artifacts
uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # 4.1.8
uses: actions/download-artifact@v4
with:
name: portDNN_build

- name: Download portBLAS build artifacts
uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # 4.1.8
uses: actions/download-artifact@v4
with:
name: portBLAS_build

- name: Download network artifacts
uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # 4.1.8
uses: actions/download-artifact@v4
with:
name: network_build

Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/run_pr_tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@ jobs:

steps:
- name: Checkout repo
uses: actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 # v4.2.0
uses: actions/checkout@v4

# installs tools, ninja, installs llvm and sets up sccahe
- name: setup-ubuntu
Expand Down Expand Up @@ -75,7 +75,7 @@ jobs:

steps:
- name: Checkout repo
uses: actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 # v4.2.0
uses: actions/checkout@v4

# installs tools, ninja, installs llvm and sets up sccahe
- name: setup-ubuntu
Expand All @@ -102,7 +102,7 @@ jobs:

steps:
- name: Checkout repo
uses: actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 # v4.2.0
uses: actions/checkout@v4

- name: setup-ubuntu-clang-format
run:
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/scorecard.yml
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,7 @@ jobs:
# Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
# format to the repository Actions tab.
- name: "Upload artifact"
uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # v4.4.0
uses: actions/upload-artifact@v4
with:
name: SARIF file
path: results.sarif
Expand Down

0 comments on commit 2fd0a22

Please sign in to comment.