diff --git a/.github/actions/build/action.yml b/.github/actions/build/action.yml index e3b5940..cba02ac 100644 --- a/.github/actions/build/action.yml +++ b/.github/actions/build/action.yml @@ -13,14 +13,14 @@ runs: using: composite steps: - name: Set up Java ${{ inputs.java-version }} - uses: actions/setup-java@v4 + uses: actions/setup-java@c1e323688fd81a25caa38c78aa6df2d33d3e20d9 # v4 with: distribution: sapmachine java-version: ${{ inputs.java-version }} cache: maven - name: Setup Maven ${{ inputs.maven-version }} - uses: stCarolas/setup-maven@v5 + uses: stCarolas/setup-maven@d6af6abeda15e98926a57b5aa970a96bb37f97d1 # v5 with: maven-version: ${{ inputs.maven-version }} diff --git a/.github/actions/prepare-next-version/action.yml b/.github/actions/prepare-next-version/action.yml index e8a2019..db785b3 100644 --- a/.github/actions/prepare-next-version/action.yml +++ b/.github/actions/prepare-next-version/action.yml @@ -19,14 +19,14 @@ runs: using: composite steps: - name: Set up Java ${{ inputs.java-version }} - uses: actions/setup-java@v4 + uses: actions/setup-java@c1e323688fd81a25caa38c78aa6df2d33d3e20d9 # v4 with: java-version: ${{ inputs.java-version }} distribution: sapmachine cache: maven - name: Setup Maven ${{ inputs.maven-version }} - uses: stCarolas/setup-maven@v5 + uses: stCarolas/setup-maven@d6af6abeda15e98926a57b5aa970a96bb37f97d1 # v5 with: maven-version: ${{ inputs.maven-version }} @@ -57,7 +57,7 @@ runs: shell: bash - name: Create Pull Request - uses: peter-evans/create-pull-request@v7 + uses: peter-evans/create-pull-request@22a9089034f40e5a961c8808d113e2c98fb63676 # v7 with: commit-message: chore/release-${{ inputs.new-version }} title: "chore(version): version ${{ inputs.new-version }}" diff --git a/.github/actions/release/action.yml b/.github/actions/release/action.yml index dfc880f..be9b31d 100644 --- a/.github/actions/release/action.yml +++ b/.github/actions/release/action.yml @@ -28,7 +28,7 @@ runs: using: composite steps: - name: Set up Java - uses: actions/setup-java@v4 + uses: actions/setup-java@c1e323688fd81a25caa38c78aa6df2d33d3e20d9 # v4 with: distribution: sapmachine java-version: ${{ inputs.java-version }} @@ -38,7 +38,7 @@ runs: server-password: MAVEN_CENTRAL_PASSWORD - name: Set up Maven ${{ inputs.maven-version }} - uses: stCarolas/setup-maven@v5 + uses: stCarolas/setup-maven@d6af6abeda15e98926a57b5aa970a96bb37f97d1 # v5 with: maven-version: ${{ inputs.maven-version }} diff --git a/.github/actions/scan-with-blackduck/action.yml b/.github/actions/scan-with-blackduck/action.yml index d9a1114..34afff5 100644 --- a/.github/actions/scan-with-blackduck/action.yml +++ b/.github/actions/scan-with-blackduck/action.yml @@ -20,14 +20,14 @@ runs: using: composite steps: - name: Set up Java ${{ inputs.java-version }} - uses: actions/setup-java@v4 + uses: actions/setup-java@c1e323688fd81a25caa38c78aa6df2d33d3e20d9 # v4 with: java-version: ${{ inputs.java-version }} distribution: sapmachine cache: maven - name: Set up Maven ${{ inputs.maven-version }} - uses: stCarolas/setup-maven@v5 + uses: stCarolas/setup-maven@d6af6abeda15e98926a57b5aa970a96bb37f97d1 # v5 with: maven-version: ${{ inputs.maven-version }} diff --git a/.github/actions/scan-with-sonar/action.yml b/.github/actions/scan-with-sonar/action.yml index 34522cf..5496401 100644 --- a/.github/actions/scan-with-sonar/action.yml +++ b/.github/actions/scan-with-sonar/action.yml @@ -20,14 +20,14 @@ runs: steps: - name: Set up Java ${{inputs.java-version}} - uses: actions/setup-java@v4 + uses: actions/setup-java@c1e323688fd81a25caa38c78aa6df2d33d3e20d9 # v4 with: java-version: ${{inputs.java-version}} distribution: sapmachine cache: maven - name: Set up Maven ${{inputs.maven-version}} - uses: stCarolas/setup-maven@v5 + uses: stCarolas/setup-maven@d6af6abeda15e98926a57b5aa970a96bb37f97d1 # v5 with: maven-version: ${{inputs.maven-version}} diff --git a/.github/workflows/blackduck.yml b/.github/workflows/blackduck.yml index 8921200..0ad3643 100644 --- a/.github/workflows/blackduck.yml +++ b/.github/workflows/blackduck.yml @@ -24,7 +24,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v5 + uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5 - name: Scan With Black Duck uses: ./.github/actions/scan-with-blackduck with: diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index d5f0843..ca39939 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -21,7 +21,7 @@ jobs: java-version: [17, 21] steps: - name: Checkout - uses: actions/checkout@v5 + uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5 - name: Build uses: ./.github/actions/build with: diff --git a/.github/workflows/prepare-next-version.yml b/.github/workflows/prepare-next-version.yml index 0166cbd..c3eb0e6 100644 --- a/.github/workflows/prepare-next-version.yml +++ b/.github/workflows/prepare-next-version.yml @@ -21,7 +21,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v5 + uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5 with: token: ${{ secrets.GH_TOKEN }} - name: Update version diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index f717e0f..0174356 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -16,14 +16,14 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v5 + uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5 - name: Build uses: ./.github/actions/build with: java-version: ${{ env.JAVA_VERSION }} maven-version: ${{ env.MAVEN_VERSION }} - name: Upload Changed Artifacts - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 with: name: root-build include-hidden-files: true @@ -36,7 +36,7 @@ jobs: needs: [build] steps: - name: Download artifact - uses: actions/download-artifact@v5 + uses: actions/download-artifact@634f93cb2916e3fdff6788551b99b062d0335ce0 # v5 with: name: root-build - name: Deploy