56
56
57
57
steps :
58
58
- name : Checkout default branch (trusted)
59
- uses : actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
59
+ uses : actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 # v4.2.0
60
60
with :
61
61
ref : ${{ github.event.repository.default_branch }}
62
62
persist-credentials : false
95
95
# Warning: since this is a privileged workflow, subsequent workflow job
96
96
# steps must take care not to execute untrusted code.
97
97
- name : Checkout pull request branch (NOT TRUSTED)
98
- uses : actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
98
+ uses : actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 # v4.2.0
99
99
with :
100
100
persist-credentials : false
101
101
ref : ${{ steps.tag.outputs.tag }}
@@ -120,7 +120,7 @@ jobs:
120
120
121
121
# Import GitHub's cache build to docker cache
122
122
- name : Copy ${{ matrix.name }} Golang cache to docker cache
123
- uses : docker/build-push-action@5cd11c3a4ced054e52742c5fd54dca954e0edd85 # v6.7 .0
123
+ uses : docker/build-push-action@32945a339266b759abcbdc89316275140b0fc960 # v6.8 .0
124
124
with :
125
125
provenance : false
126
126
context : /tmp/.cache/${{ matrix.name }}
@@ -135,7 +135,7 @@ jobs:
135
135
# main branch pushes
136
136
- name : CI Build ${{ matrix.name }}
137
137
if : ${{ github.event_name != 'pull_request_target' && !startsWith(github.ref_name, 'ft/') }}
138
- uses : docker/build-push-action@5cd11c3a4ced054e52742c5fd54dca954e0edd85 # v6.7 .0
138
+ uses : docker/build-push-action@32945a339266b759abcbdc89316275140b0fc960 # v6.8 .0
139
139
id : docker_build_ci
140
140
with :
141
141
provenance : false
@@ -155,7 +155,7 @@ jobs:
155
155
156
156
- name : CI race detection Build ${{ matrix.name }}
157
157
if : ${{ github.event_name != 'pull_request_target' && !startsWith(github.ref_name, 'ft/') }}
158
- uses : docker/build-push-action@5cd11c3a4ced054e52742c5fd54dca954e0edd85 # v6.7 .0
158
+ uses : docker/build-push-action@32945a339266b759abcbdc89316275140b0fc960 # v6.8 .0
159
159
id : docker_build_ci_detect_race_condition
160
160
with :
161
161
provenance : false
@@ -177,7 +177,7 @@ jobs:
177
177
178
178
- name : CI Unstripped Binaries Build ${{ matrix.name }}
179
179
if : ${{ github.event_name != 'pull_request_target' && !startsWith(github.ref_name, 'ft/') }}
180
- uses : docker/build-push-action@5cd11c3a4ced054e52742c5fd54dca954e0edd85 # v6.7 .0
180
+ uses : docker/build-push-action@32945a339266b759abcbdc89316275140b0fc960 # v6.8 .0
181
181
id : docker_build_ci_unstripped
182
182
with :
183
183
provenance : false
@@ -287,7 +287,7 @@ jobs:
287
287
# PR or feature branch updates
288
288
- name : CI Build ${{ matrix.name }}
289
289
if : ${{ github.event_name == 'pull_request_target' || (github.event_name == 'push' && startsWith(github.ref_name, 'ft/')) }}
290
- uses : docker/build-push-action@5cd11c3a4ced054e52742c5fd54dca954e0edd85 # v6.7 .0
290
+ uses : docker/build-push-action@32945a339266b759abcbdc89316275140b0fc960 # v6.8 .0
291
291
id : docker_build_ci_pr
292
292
with :
293
293
provenance : false
@@ -303,7 +303,7 @@ jobs:
303
303
304
304
- name : CI race detection Build ${{ matrix.name }}
305
305
if : ${{ github.event_name == 'pull_request_target' || (github.event_name == 'push' && startsWith(github.ref_name, 'ft/')) }}
306
- uses : docker/build-push-action@5cd11c3a4ced054e52742c5fd54dca954e0edd85 # v6.7 .0
306
+ uses : docker/build-push-action@32945a339266b759abcbdc89316275140b0fc960 # v6.8 .0
307
307
id : docker_build_ci_pr_detect_race_condition
308
308
with :
309
309
provenance : false
@@ -321,7 +321,7 @@ jobs:
321
321
322
322
- name : CI Unstripped Binaries Build ${{ matrix.name }}
323
323
if : ${{ github.event_name == 'pull_request_target' || (github.event_name == 'push' && startsWith(github.ref_name, 'ft/')) }}
324
- uses : docker/build-push-action@5cd11c3a4ced054e52742c5fd54dca954e0edd85 # v6.7 .0
324
+ uses : docker/build-push-action@32945a339266b759abcbdc89316275140b0fc960 # v6.8 .0
325
325
id : docker_build_ci_pr_unstripped
326
326
with :
327
327
provenance : false
@@ -412,7 +412,7 @@ jobs:
412
412
# Store docker's golang's cache build locally only on the main branch
413
413
- name : Store ${{ matrix.name }} Golang cache build locally
414
414
if : ${{ github.event_name != 'pull_request_target' && steps.cache.outputs.cache-hit != 'true' && github.ref_name == github.event.repository.default_branch }}
415
- uses : docker/build-push-action@5cd11c3a4ced054e52742c5fd54dca954e0edd85 # v6.7 .0
415
+ uses : docker/build-push-action@32945a339266b759abcbdc89316275140b0fc960 # v6.8 .0
416
416
with :
417
417
provenance : false
418
418
context : .
@@ -438,7 +438,7 @@ jobs:
438
438
image-digests :
439
439
if : ${{ always() }}
440
440
name : Display Digests
441
- runs-on : ubuntu-22 .04
441
+ runs-on : ubuntu-24 .04
442
442
needs : build-and-push-prs
443
443
steps :
444
444
- name : Downloading Image Digests
0 commit comments