From bf6da728ba20925756a880b9a80ae4b7478182b6 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 4 Aug 2026 10:15:44 +0000 Subject: [PATCH] Bump the actions group across 4 directories with 13 updates Bumps the actions group with 10 updates in the / directory: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `2.7.0` | `7.0.1` | | [tj-actions/changed-files](https://github.com/tj-actions/changed-files) | `b1ba699b304f2083b602164e06a89b868c84f076` | `934b2d2c7e653bb8c968afed5a0428617f09aa24` | | [actions/github-script](https://github.com/actions/github-script) | `3.2.0` | `9.0.0` | | [mshick/add-pr-comment](https://github.com/mshick/add-pr-comment) | `2.8.2` | `3.12.0` | | [tobyhs/codemention](https://github.com/tobyhs/codemention) | `ebac5877393ab8693fd73b42708c8552043e9a3b` | `d6fa8b52ca8725f2658160ac67be61adeb95b468` | | [actions/setup-node](https://github.com/actions/setup-node) | `2.5.2` | `7.0.0` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.6.2` | `7.0.1` | | [rtCamp/action-slack-notify](https://github.com/rtcamp/action-slack-notify) | `2.3.3` | `2.4.0` | | [actions/stale](https://github.com/actions/stale) | `4.1.1` | `11.0.0` | | [codecov/codecov-action](https://github.com/codecov/codecov-action) | `1.5.2` | `7.0.0` | Bumps the actions group with 1 update in the /.github/actions/setup-mise directory: [jdx/mise-action](https://github.com/jdx/mise-action). Bumps the actions group with 2 updates in the /.github/internal-actions/notify-slack-on-fail-or-recover directory: [actions/github-script](https://github.com/actions/github-script) and [rtCamp/action-slack-notify](https://github.com/rtcamp/action-slack-notify). Bumps the actions group with 2 updates in the /.github/internal-actions/setup-gcloud directory: [google-github-actions/auth](https://github.com/google-github-actions/auth) and [google-github-actions/setup-gcloud](https://github.com/google-github-actions/setup-gcloud). Updates `actions/checkout` from 2.7.0 to 7.0.1 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/v2.7.0...3d3c42e5aac5ba805825da76410c181273ba90b1) Updates `tj-actions/changed-files` from b1ba699b304f2083b602164e06a89b868c84f076 to 934b2d2c7e653bb8c968afed5a0428617f09aa24 - [Release notes](https://github.com/tj-actions/changed-files/releases) - [Changelog](https://github.com/tj-actions/changed-files/blob/main/HISTORY.md) - [Commits](https://github.com/tj-actions/changed-files/compare/b1ba699b304f2083b602164e06a89b868c84f076...934b2d2c7e653bb8c968afed5a0428617f09aa24) Updates `actions/github-script` from 3.2.0 to 9.0.0 - [Release notes](https://github.com/actions/github-script/releases) - [Commits](https://github.com/actions/github-script/compare/v3.2.0...3a2844b7e9c422d3c10d287c895573f7108da1b3) Updates `mshick/add-pr-comment` from 2.8.2 to 3.12.0 - [Release notes](https://github.com/mshick/add-pr-comment/releases) - [Changelog](https://github.com/mshick/add-pr-comment/blob/main/CHANGELOG.md) - [Commits](https://github.com/mshick/add-pr-comment/compare/b8f338c590a895d50bcbfa6c5859251edc8952fc...ec328af66588ab8f77cdeb2c264f14aba45bbf59) Updates `tobyhs/codemention` from ebac5877393ab8693fd73b42708c8552043e9a3b to d6fa8b52ca8725f2658160ac67be61adeb95b468 - [Release notes](https://github.com/tobyhs/codemention/releases) - [Commits](https://github.com/tobyhs/codemention/compare/ebac5877393ab8693fd73b42708c8552043e9a3b...d6fa8b52ca8725f2658160ac67be61adeb95b468) Updates `actions/setup-node` from 2.5.2 to 7.0.0 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](https://github.com/actions/setup-node/compare/v2.5.2...820762786026740c76f36085b0efc47a31fe5020) Updates `actions/upload-artifact` from 4.6.2 to 7.0.1 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](https://github.com/actions/upload-artifact/compare/ea165f8d65b6e75b540449e92b4886f43607fa02...043fb46d1a93c77aae656e7c1c64a875d1fc6a0a) Updates `rtCamp/action-slack-notify` from 2.3.3 to 2.4.0 - [Release notes](https://github.com/rtcamp/action-slack-notify/releases) - [Commits](https://github.com/rtcamp/action-slack-notify/compare/e31e87e03dd19038e411e38ae27cbad084a90661...33ca3be66c6f378fe1610fd1d5258632dbed5e58) Updates `actions/stale` from 4.1.1 to 11.0.0 - [Release notes](https://github.com/actions/stale/releases) - [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/stale/compare/a20b814fb01b71def3bd6f56e7494d667ddf28da...4391f3da665fdf50b6810c1a66712fb9ba21aa93) Updates `codecov/codecov-action` from 1.5.2 to 7.0.0 - [Release notes](https://github.com/codecov/codecov-action/releases) - [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/codecov/codecov-action/compare/29386c70ef20e286228c72b668a06fd0e8399192...fb8b3582c8e4def4969c97caa2f19720cb33a72f) Updates `actions/github-script` from 3.2.0 to 9.0.0 - [Release notes](https://github.com/actions/github-script/releases) - [Commits](https://github.com/actions/github-script/compare/v3.2.0...3a2844b7e9c422d3c10d287c895573f7108da1b3) Updates `rtCamp/action-slack-notify` from 2.3.3 to 2.4.0 - [Release notes](https://github.com/rtcamp/action-slack-notify/releases) - [Commits](https://github.com/rtcamp/action-slack-notify/compare/e31e87e03dd19038e411e38ae27cbad084a90661...33ca3be66c6f378fe1610fd1d5258632dbed5e58) Updates `jdx/mise-action` from 3.5.1 to 4.2.4 - [Release notes](https://github.com/jdx/mise-action/releases) - [Changelog](https://github.com/jdx/mise-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/jdx/mise-action/compare/146a28175021df8ca24f8ee1828cc2a60f980bd5...7e36c90d9ab29c415a2384db3006f3ec8a8cc654) Updates `actions/github-script` from 6.4.1 to 9.0.0 - [Release notes](https://github.com/actions/github-script/releases) - [Commits](https://github.com/actions/github-script/compare/v3.2.0...3a2844b7e9c422d3c10d287c895573f7108da1b3) Updates `rtCamp/action-slack-notify` from 2.3.3 to 2.4.0 - [Release notes](https://github.com/rtcamp/action-slack-notify/releases) - [Commits](https://github.com/rtcamp/action-slack-notify/compare/e31e87e03dd19038e411e38ae27cbad084a90661...33ca3be66c6f378fe1610fd1d5258632dbed5e58) Updates `actions/github-script` from 6.4.1 to 9.0.0 - [Release notes](https://github.com/actions/github-script/releases) - [Commits](https://github.com/actions/github-script/compare/v3.2.0...3a2844b7e9c422d3c10d287c895573f7108da1b3) Updates `rtCamp/action-slack-notify` from 2.3.3 to 2.4.0 - [Release notes](https://github.com/rtcamp/action-slack-notify/releases) - [Commits](https://github.com/rtcamp/action-slack-notify/compare/e31e87e03dd19038e411e38ae27cbad084a90661...33ca3be66c6f378fe1610fd1d5258632dbed5e58) Updates `google-github-actions/auth` from 2.1.13 to 3.0.0 - [Release notes](https://github.com/google-github-actions/auth/releases) - [Changelog](https://github.com/google-github-actions/auth/blob/main/CHANGELOG.md) - [Commits](https://github.com/google-github-actions/auth/compare/c200f3691d83b41bf9bbd8638997a462592937ed...7c6bc770dae815cd3e89ee6cdf493a5fab2cc093) Updates `google-github-actions/setup-gcloud` from 2.2.1 to 3.0.1 - [Release notes](https://github.com/google-github-actions/setup-gcloud/releases) - [Changelog](https://github.com/google-github-actions/setup-gcloud/blob/main/CHANGELOG.md) - [Commits](https://github.com/google-github-actions/setup-gcloud/compare/e427ad8a34f8676edf47cf7d7925499adf3eb74f...aa5489c8933f4cc7a4f7d45035b3b1440c9c10db) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/github-script dependency-version: 9.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/github-script dependency-version: 9.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/github-script dependency-version: 9.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/github-script dependency-version: 9.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/setup-node dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/stale dependency-version: 11.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/upload-artifact dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: codecov/codecov-action dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: google-github-actions/auth dependency-version: 3.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: google-github-actions/setup-gcloud dependency-version: 3.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: jdx/mise-action dependency-version: 4.2.3 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: mshick/add-pr-comment dependency-version: 3.12.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: rtCamp/action-slack-notify dependency-version: 2.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: rtCamp/action-slack-notify dependency-version: 2.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: rtCamp/action-slack-notify dependency-version: 2.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: rtCamp/action-slack-notify dependency-version: 2.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: tj-actions/changed-files dependency-version: 934b2d2c7e653bb8c968afed5a0428617f09aa24 dependency-type: direct:production dependency-group: actions - dependency-name: tobyhs/codemention dependency-version: '0887fe62efa60b8052d9995c9791e1243da6653c' dependency-type: direct:production dependency-group: actions ... Signed-off-by: dependabot[bot] --- .github/actions/setup-mise/action.yml | 2 +- .../notify-slack-on-fail-or-recover/action.yml | 6 +++--- .github/internal-actions/setup-gcloud/action.yml | 4 ++-- .github/workflows/build-and-deploy-worker.yml | 2 +- .github/workflows/changelog.yml | 8 ++++---- .github/workflows/codemention.yml | 2 +- .github/workflows/expo-code-review-command.yml | 4 ++-- .github/workflows/expo-code-review-dismiss.yml | 4 ++-- .github/workflows/expo-code-review.yml | 6 +++--- .github/workflows/issue-triage.yml | 10 +++++----- .github/workflows/license.yml | 2 +- .github/workflows/move-eas-build-tag.yml | 2 +- .github/workflows/release.yml | 8 ++++---- .github/workflows/stale-issues.yml | 2 +- .github/workflows/test-graphql.yml | 2 +- .github/workflows/test-scripts.yml | 2 +- .github/workflows/test.yml | 6 +++--- .github/workflows/trigger-release.yml | 2 +- .github/workflows/worker-system-tests.yml | 2 +- .github/workflows/worker.yml | 4 ++-- 20 files changed, 40 insertions(+), 40 deletions(-) diff --git a/.github/actions/setup-mise/action.yml b/.github/actions/setup-mise/action.yml index b1dadb4299..78644fd7c5 100644 --- a/.github/actions/setup-mise/action.yml +++ b/.github/actions/setup-mise/action.yml @@ -4,7 +4,7 @@ description: Install tools via mise runs: using: "composite" steps: - - uses: jdx/mise-action@146a28175021df8ca24f8ee1828cc2a60f980bd5 # v3.5.1 + - uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4 with: install: true cache: true diff --git a/.github/internal-actions/notify-slack-on-fail-or-recover/action.yml b/.github/internal-actions/notify-slack-on-fail-or-recover/action.yml index 3396653f33..e0c6ad3d7e 100644 --- a/.github/internal-actions/notify-slack-on-fail-or-recover/action.yml +++ b/.github/internal-actions/notify-slack-on-fail-or-recover/action.yml @@ -12,7 +12,7 @@ runs: using: 'composite' steps: - name: Get previous workflow run status - uses: actions/github-script@d7906e4ad0b1822421a7e6a35d5ca353c962f410 # v6 + uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 id: run-status with: script: | @@ -28,7 +28,7 @@ runs: - name: Send Slack Success Notification if: fromJSON(steps.run-status.outputs.result).previous == 'failure' && fromJSON(steps.run-status.outputs.result).current == 'success' - uses: rtCamp/action-slack-notify@e31e87e03dd19038e411e38ae27cbad084a90661 # v2 + uses: rtCamp/action-slack-notify@33ca3be66c6f378fe1610fd1d5258632dbed5e58 # v2 env: SLACK_CHANNEL: ${{ inputs.channel }} SLACK_COLOR: good @@ -41,7 +41,7 @@ runs: - name: Send Slack Failure Notification if: fromJSON(steps.run-status.outputs.result).current == 'failure' - uses: rtCamp/action-slack-notify@e31e87e03dd19038e411e38ae27cbad084a90661 # v2 + uses: rtCamp/action-slack-notify@33ca3be66c6f378fe1610fd1d5258632dbed5e58 # v2 env: SLACK_CHANNEL: ${{ inputs.channel }} SLACK_COLOR: danger diff --git a/.github/internal-actions/setup-gcloud/action.yml b/.github/internal-actions/setup-gcloud/action.yml index 426133e807..388d378535 100644 --- a/.github/internal-actions/setup-gcloud/action.yml +++ b/.github/internal-actions/setup-gcloud/action.yml @@ -4,13 +4,13 @@ runs: using: "composite" steps: - name: Auth gcloud - uses: google-github-actions/auth@c200f3691d83b41bf9bbd8638997a462592937ed # v2 + uses: google-github-actions/auth@7c6bc770dae815cd3e89ee6cdf493a5fab2cc093 # v3.0.0 with: workload_identity_provider: 'projects/321830142373/locations/global/workloadIdentityPools/github/providers/expo' project_id: exponentjs - name: Setup gcloud - uses: google-github-actions/setup-gcloud@e427ad8a34f8676edf47cf7d7925499adf3eb74f # v2 + uses: google-github-actions/setup-gcloud@aa5489c8933f4cc7a4f7d45035b3b1440c9c10db # v3.0.1 with: version: 548.0.0 project_id: exponentjs diff --git a/.github/workflows/build-and-deploy-worker.yml b/.github/workflows/build-and-deploy-worker.yml index 87b4ef90c4..8c7e039522 100644 --- a/.github/workflows/build-and-deploy-worker.yml +++ b/.github/workflows/build-and-deploy-worker.yml @@ -23,7 +23,7 @@ jobs: permissions: id-token: write steps: - - uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4 - uses: ./.github/actions/setup-mise diff --git a/.github/workflows/changelog.yml b/.github/workflows/changelog.yml index 64662326a4..b9123e31a9 100644 --- a/.github/workflows/changelog.yml +++ b/.github/workflows/changelog.yml @@ -18,19 +18,19 @@ jobs: name: Check CHANGELOG.md updated runs-on: ubuntu-latest steps: - - uses: actions/checkout@ee0669bd1cc54295c223e0bb666b733df41de1c5 # v2 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v2 - name: Check if CHANGELOG.md was updated id: changelog-updated - uses: tj-actions/changed-files@b1ba699b304f2083b602164e06a89b868c84f076 + uses: tj-actions/changed-files@934b2d2c7e653bb8c968afed5a0428617f09aa24 with: files: CHANGELOG.md - name: Fail if CHANGELOG.md was not updated and the "no changelog" label is absent if: steps.changelog-updated.outputs.any_changed == 'false' && !contains(github.event.pull_request.labels.*.name, 'no changelog') - uses: actions/github-script@d7906e4ad0b1822421a7e6a35d5ca353c962f410 # v6 + uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: script: | core.setFailed('Please add a changelog entry!') - - uses: mshick/add-pr-comment@b8f338c590a895d50bcbfa6c5859251edc8952fc # v2.8.2 + - uses: mshick/add-pr-comment@ec328af66588ab8f77cdeb2c264f14aba45bbf59 # v3.12.0 if: always() with: message-id: changelog-entry-check diff --git a/.github/workflows/codemention.yml b/.github/workflows/codemention.yml index adcef112c9..fdd29a0a83 100644 --- a/.github/workflows/codemention.yml +++ b/.github/workflows/codemention.yml @@ -15,6 +15,6 @@ jobs: # Pinned to a commit SHA (not a tag or branch) because this runs under # pull_request_target with a write-scoped token — a re-pointed tag or # moving branch would allow unreviewed upstream code to run here. - - uses: tobyhs/codemention@ebac5877393ab8693fd73b42708c8552043e9a3b # post-v1.5.2 + - uses: tobyhs/codemention@d6fa8b52ca8725f2658160ac67be61adeb95b468 # post-v1.5.2 with: githubToken: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/expo-code-review-command.yml b/.github/workflows/expo-code-review-command.yml index 86fd50815e..1b551fb5aa 100644 --- a/.github/workflows/expo-code-review-command.yml +++ b/.github/workflows/expo-code-review-command.yml @@ -83,7 +83,7 @@ jobs: # model as the pull_request workflow. - name: Checkout (base ref only — never the PR head) if: steps.cmd.outputs.run == 'true' - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 1 # The CLI's git fetches authenticate through `gh` from GH_TOKEN; keep the @@ -98,7 +98,7 @@ jobs: - name: Set up Node if: steps.cmd.outputs.run == 'true' - uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: 24 # No yarn install here (runs via npx) — disable the auto yarn cache so the diff --git a/.github/workflows/expo-code-review-dismiss.yml b/.github/workflows/expo-code-review-dismiss.yml index c3557aa837..4f7b3c84b6 100644 --- a/.github/workflows/expo-code-review-dismiss.yml +++ b/.github/workflows/expo-code-review-dismiss.yml @@ -77,7 +77,7 @@ jobs: # no model secret. - name: Checkout (base ref only) if: steps.cmd.outputs.run == 'true' - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 1 # The CLI's git fetches authenticate through `gh` from GH_TOKEN; keep the @@ -92,7 +92,7 @@ jobs: - name: Set up Node if: steps.cmd.outputs.run == 'true' - uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: 24 # No yarn install here (runs via npx) — disable the auto yarn cache so the diff --git a/.github/workflows/expo-code-review.yml b/.github/workflows/expo-code-review.yml index 8b1f1e4e9e..9d7b530153 100644 --- a/.github/workflows/expo-code-review.yml +++ b/.github/workflows/expo-code-review.yml @@ -88,7 +88,7 @@ jobs: # token never lands in .git/config. - name: Checkout (base commit only — never the PR head) if: steps.resolve.outputs.run == 'true' - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 # The diff comes from the API (`gh pr diff`), so a shallow checkout is enough. with: ref: ${{ github.event.pull_request.base.sha }} @@ -105,7 +105,7 @@ jobs: - name: Set up Node if: steps.resolve.outputs.run == 'true' - uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: 24 # We install nothing with yarn (the reviewer runs via npx), so disable @@ -178,7 +178,7 @@ jobs: # still uploads whatever it logged (that's when the data matters most). - name: Upload review run log if: always() && steps.resolve.outputs.run == 'true' - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: review-run-log-pr${{ github.event.pull_request.number }} path: .expo-code-review/.runs/reviews.jsonl diff --git a/.github/workflows/issue-triage.yml b/.github/workflows/issue-triage.yml index d7f27bdb0e..fe415bd80e 100644 --- a/.github/workflows/issue-triage.yml +++ b/.github/workflows/issue-triage.yml @@ -8,7 +8,7 @@ jobs: runs-on: ubuntu-20.04 if: "${{ contains(github.event.label.name, 'incomplete issue: missing or invalid repro') }}" steps: - - uses: actions/github-script@ffc2c79a5b2490bd33e0a41c1de74b877714d736 # v3 + - uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: github-token: ${{ secrets.EXPO_BOT_GITHUB_TOKEN }} script: | @@ -52,7 +52,7 @@ jobs: runs-on: ubuntu-20.04 if: "${{ contains(github.event.label.name, 'incomplete issue: missing info') }}" steps: - - uses: actions/github-script@ffc2c79a5b2490bd33e0a41c1de74b877714d736 # v3 + - uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: github-token: ${{ secrets.EXPO_BOT_GITHUB_TOKEN }} script: | @@ -81,7 +81,7 @@ jobs: runs-on: ubuntu-20.04 if: github.event.label.name == 'issue accepted' steps: - - uses: actions/github-script@ffc2c79a5b2490bd33e0a41c1de74b877714d736 # v3 + - uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: github-token: ${{ secrets.EXPO_BOT_GITHUB_TOKEN }} script: | @@ -98,7 +98,7 @@ jobs: runs-on: ubuntu-20.04 if: "${{ contains(github.event.label.name, 'invalid issue: question') }}" steps: - - uses: actions/github-script@ffc2c79a5b2490bd33e0a41c1de74b877714d736 # v3 + - uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: github-token: ${{ secrets.EXPO_BOT_GITHUB_TOKEN }} script: | @@ -126,7 +126,7 @@ jobs: runs-on: ubuntu-20.04 if: "${{ contains(github.event.label.name, 'invalid issue: feature request') }}" steps: - - uses: actions/github-script@ffc2c79a5b2490bd33e0a41c1de74b877714d736 # v3 + - uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: github-token: ${{ secrets.EXPO_BOT_GITHUB_TOKEN }} script: | diff --git a/.github/workflows/license.yml b/.github/workflows/license.yml index c0564ae931..6441b3b2d2 100644 --- a/.github/workflows/license.yml +++ b/.github/workflows/license.yml @@ -14,7 +14,7 @@ jobs: runs-on: ubuntu-latest name: Update BSL change date steps: - - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4 with: token: ${{ secrets.EXPO_BOT_PAT }} - name: Check last commit date diff --git a/.github/workflows/move-eas-build-tag.yml b/.github/workflows/move-eas-build-tag.yml index 43e43700f8..42445998bc 100644 --- a/.github/workflows/move-eas-build-tag.yml +++ b/.github/workflows/move-eas-build-tag.yml @@ -32,7 +32,7 @@ jobs: INPUT_DRY_RUN: ${{ github.event.inputs.dry_run }} INPUT_STAGING_ONLY: ${{ github.event.inputs.staging_only }} steps: - - uses: actions/setup-node@7c12f8017d5436eb855f1ed4399f037a36fbd9e8 # v2 + - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: registry-url: "https://registry.npmjs.org/" scope: "expo" diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 0f15833c36..fe2e3ab4d4 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -29,7 +29,7 @@ jobs: permissions: id-token: write steps: - - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4 - uses: ./.github/actions/setup-mise - name: Install dependencies run: yarn install --immutable @@ -56,7 +56,7 @@ jobs: - name: Resolve version run: echo "EAS_CLI_VERSION=$(jq -r .version lerna.json)" >> $GITHUB_ENV - name: Slack reminder to add npm tags manually - uses: rtCamp/action-slack-notify@e31e87e03dd19038e411e38ae27cbad084a90661 # v2 + uses: rtCamp/action-slack-notify@33ca3be66c6f378fe1610fd1d5258632dbed5e58 # v2 env: SLACK_CHANNEL: eas-cli SLACK_COLOR: warning @@ -78,7 +78,7 @@ jobs: permissions: contents: write steps: - - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4 with: token: ${{ secrets.EXPO_BOT_PAT }} - uses: ./.github/actions/setup-mise @@ -111,7 +111,7 @@ jobs: cat /tmp/changelog.slack.md >> $GITHUB_ENV echo 'EOF' >> $GITHUB_ENV - name: Slack Notification - uses: rtCamp/action-slack-notify@e31e87e03dd19038e411e38ae27cbad084a90661 # v2 + uses: rtCamp/action-slack-notify@33ca3be66c6f378fe1610fd1d5258632dbed5e58 # v2 env: SLACK_CHANNEL: eas-cli SLACK_COLOR: ${{ job.status }} diff --git a/.github/workflows/stale-issues.yml b/.github/workflows/stale-issues.yml index 110e8c1f1b..3777d3195d 100644 --- a/.github/workflows/stale-issues.yml +++ b/.github/workflows/stale-issues.yml @@ -8,7 +8,7 @@ jobs: close-issues: runs-on: ubuntu-latest steps: - - uses: actions/stale@a20b814fb01b71def3bd6f56e7494d667ddf28da # v4 + - uses: actions/stale@4391f3da665fdf50b6810c1a66712fb9ba21aa93 # v11.0.0 with: ascending: false operations-per-run: 300 diff --git a/.github/workflows/test-graphql.yml b/.github/workflows/test-graphql.yml index 38800d27bd..a7ffffa5ee 100644 --- a/.github/workflows/test-graphql.yml +++ b/.github/workflows/test-graphql.yml @@ -17,7 +17,7 @@ jobs: name: Ensure GraphQL schema and generated code is up-to-date runs-on: ubuntu-latest steps: - - uses: actions/checkout@ee0669bd1cc54295c223e0bb666b733df41de1c5 # v2 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v2 - name: Setup tools uses: ./.github/actions/setup-mise - run: yarn install --immutable diff --git a/.github/workflows/test-scripts.yml b/.github/workflows/test-scripts.yml index 42c7a8aac8..c9283fa008 100644 --- a/.github/workflows/test-scripts.yml +++ b/.github/workflows/test-scripts.yml @@ -21,7 +21,7 @@ jobs: test: runs-on: ubuntu-latest steps: - - uses: actions/checkout@ee0669bd1cc54295c223e0bb666b733df41de1c5 # v2 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v2 - name: Setup tools uses: ./.github/actions/setup-mise - run: yarn install --immutable diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index a4458e79c3..a901dc3c00 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -21,7 +21,7 @@ jobs: coverage: true name: Test with Node ${{ matrix.node }} steps: - - uses: actions/checkout@ee0669bd1cc54295c223e0bb666b733df41de1c5 # v2 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v2 - name: Setup tools uses: ./.github/actions/setup-mise env: @@ -66,7 +66,7 @@ jobs: working-directory: ./scripts env: YARN_ENABLE_HARDENED_MODE: ${{ matrix.coverage == true && '1' || '0' }} - - uses: codecov/codecov-action@29386c70ef20e286228c72b668a06fd0e8399192 # v1 + - uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0 if: ${{ matrix.coverage }} with: token: ${{ secrets.CODECOV_TOKEN }} @@ -79,7 +79,7 @@ jobs: name: Notify Slack if: ${{ github.ref == 'refs/heads/main' && always() }} steps: - - uses: actions/checkout@ee0669bd1cc54295c223e0bb666b733df41de1c5 # v2 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v2 - name: Notify Slack uses: ./.github/internal-actions/notify-slack-on-fail-or-recover with: diff --git a/.github/workflows/trigger-release.yml b/.github/workflows/trigger-release.yml index 09ff440525..8000660299 100644 --- a/.github/workflows/trigger-release.yml +++ b/.github/workflows/trigger-release.yml @@ -22,7 +22,7 @@ jobs: INPUT_VERSION: ${{ github.event.inputs.version }} INPUT_DRY_RUN: ${{ github.event.inputs.dry_run }} steps: - - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4 with: ref: main fetch-depth: 0 diff --git a/.github/workflows/worker-system-tests.yml b/.github/workflows/worker-system-tests.yml index 4e04b98c0c..ab987c41fd 100644 --- a/.github/workflows/worker-system-tests.yml +++ b/.github/workflows/worker-system-tests.yml @@ -11,7 +11,7 @@ jobs: EXPO_TOKEN: ${{ secrets.STAGING_EXPO_DEV_EXPO_SERVICES_GITHUB_ROBOT_ACCESS_TOKEN }} EXPO_STAGING: "1" steps: - - uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4 - uses: ./.github/actions/setup-mise diff --git a/.github/workflows/worker.yml b/.github/workflows/worker.yml index 7a2f5f065f..3589a6fe5e 100644 --- a/.github/workflows/worker.yml +++ b/.github/workflows/worker.yml @@ -24,7 +24,7 @@ jobs: worker-checks: runs-on: ubuntu-latest steps: - - uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4 - uses: ./.github/actions/setup-mise @@ -71,7 +71,7 @@ jobs: - deploy-worker-production if: github.ref == 'refs/heads/main' && always() && !cancelled() steps: - - uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4 - name: Notify Slack uses: ./.github/internal-actions/notify-slack-on-fail-or-recover