Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/auto-merge.yml
Original file line number Diff line number Diff line change
Expand Up @@ -57,4 +57,4 @@ jobs:
contents: read
id-token: write
# SHA-pinned, per org policy — never a branch. The broker door pins this SHA too.
uses: bounded-systems/.github/.github/workflows/_auto-merge.yml@a0330aea1a9fc899ff1002bf52d20ef8d9b2edad
uses: bounded-systems/.github/.github/workflows/_auto-merge.yml@1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c
2 changes: 1 addition & 1 deletion .github/workflows/claim-sweep.yml
Original file line number Diff line number Diff line change
Expand Up @@ -69,7 +69,7 @@ concurrency:
jobs:
sweep:
# SHA-pinned, per org policy — never a branch.
uses: bounded-systems/.github/.github/workflows/_claim-sweep.yml@953ed46c6560abe5366fbcf1235023dc46192776
uses: bounded-systems/.github/.github/workflows/_claim-sweep.yml@1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c
permissions:
contents: read
issues: write
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/deps.yml
Original file line number Diff line number Diff line change
Expand Up @@ -43,4 +43,4 @@ jobs:
osv:
# SHA-pinned per org policy. `# main` records what the SHA was at the time, so a
# reviewer can tell an intentional bump from a drifted one.
uses: bounded-systems/ci-workflows/.github/workflows/osv-scan.yml@ce6310f52e47fcd3f536bfd267edc62974ecfc9f # main
uses: bounded-systems/ci-workflows/.github/workflows/osv-scan.yml@752eb5ca508e4bdcb895ae4f4f2b423ff0726c7b # main
2 changes: 1 addition & 1 deletion .github/workflows/front-desk-add.yml
Original file line number Diff line number Diff line change
Expand Up @@ -59,7 +59,7 @@ jobs:
id: app-token
if: ${{ vars.CF_BROKER_URL != '' }}
continue-on-error: true
uses: bounded-systems/.github/.github/actions/broker-gh-token@953ed46c6560abe5366fbcf1235023dc46192776 # broker-gh-token (prx-26bq), .github#109
uses: bounded-systems/.github/.github/actions/broker-gh-token@1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c # broker-gh-token (prx-26bq), .github#109
with:
app: front-desk
broker-url: ${{ vars.CF_BROKER_URL }}
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/pr-claim.yml
Original file line number Diff line number Diff line change
Expand Up @@ -81,4 +81,4 @@ jobs:
issues: read
pull-requests: read
# SHA-pinned, per org policy — never a branch.
uses: bounded-systems/.github/.github/workflows/_pr-claim.yml@bc4cb7dada47cc59eed416372a4851201bd6f503
uses: bounded-systems/.github/.github/workflows/_pr-claim.yml@1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c
6 changes: 3 additions & 3 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -47,7 +47,7 @@ jobs:
trusted-public-keys = cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY=

- name: Setup Cachix
uses: cachix/cachix-action@5f2d7c5294214f71b873db4b969586b980625e71 # v17
uses: cachix/cachix-action@38b082610b782e7e93e209c35fd730d399dee866 # v17
with:
name: hooksmith
authToken: '${{ secrets.CACHIX_AUTH_TOKEN }}'
Expand Down Expand Up @@ -220,7 +220,7 @@ jobs:
github_access_token: ${{ secrets.GITHUB_TOKEN }}

- name: Setup Cachix
uses: cachix/cachix-action@5f2d7c5294214f71b873db4b969586b980625e71 # v17
uses: cachix/cachix-action@38b082610b782e7e93e209c35fd730d399dee866 # v17
with:
name: hooksmith
authToken: '${{ secrets.CACHIX_AUTH_TOKEN }}'
Expand Down Expand Up @@ -295,7 +295,7 @@ jobs:
EOF

- name: Create GitHub Release
uses: softprops/action-gh-release@3d0d9888cb7fd7b750713d6e236d1fcb99157228 # v3.0.2
uses: softprops/action-gh-release@efb35369e0ad2afab669f228072c1b0d510eae64 # v3.0.3
if: startsWith(github.ref, 'refs/tags/')
with:
files: release-final/*
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/standard.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ permissions:
contents: read
jobs:
standard:
uses: bounded-systems/.github/.github/workflows/repo-standard.yml@953ed46c6560abe5366fbcf1235023dc46192776
uses: bounded-systems/.github/.github/workflows/repo-standard.yml@1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c
with:
security: true
test: true
Expand Down
Loading