diff --git a/.github/actions/setup_node/action.yml b/.github/actions/setup_node/action.yml index ba9e0b2939..913649d917 100644 --- a/.github/actions/setup_node/action.yml +++ b/.github/actions/setup_node/action.yml @@ -18,7 +18,7 @@ runs: version: 10 run_install: ${{ inputs.run-install }} - - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4 + - uses: actions/setup-node@395ad3262231945c25e8478fd5baf05154b1d79f # v6 with: node-version: 22.20.0 cache: 'pnpm' diff --git a/.github/workflows/check-backend.yml b/.github/workflows/check-backend.yml index a3a2d4e51b..2e490da2b6 100644 --- a/.github/workflows/check-backend.yml +++ b/.github/workflows/check-backend.yml @@ -8,7 +8,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 + uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6 with: fetch-depth: 0 @@ -26,7 +26,7 @@ jobs: cd ../hivemq-edge - name: Setup Java - uses: actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 # v4 + uses: actions/setup-java@f2beeb24e141e01a676f977032f5a29d81c9e27e # v5 with: distribution: 'adopt' java-version: '21' @@ -59,7 +59,7 @@ jobs: debug-mode: true - name: Upload coverage report - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 + uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5 with: name: coverage-java path: build/reports/jacoco/jacocoMergedReport/html diff --git a/.github/workflows/check-frontend.yml b/.github/workflows/check-frontend.yml index a47c5bcbd7..a0ed5e780d 100644 --- a/.github/workflows/check-frontend.yml +++ b/.github/workflows/check-frontend.yml @@ -19,7 +19,7 @@ jobs: runs-on: ubuntu-latest steps: - name: 👓 Checkout repository - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 + uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6 - name: 🏗️ Setup node environment uses: ./.github/actions/setup_node @@ -37,7 +37,7 @@ jobs: runs-on: ubuntu-latest steps: - name: 👓 Checkout repository - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 + uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6 - name: 🏗️ Setup node environment uses: ./.github/actions/setup_node @@ -48,7 +48,7 @@ jobs: run: pnpm test:coverage - name: 💾 Upload Vitest Code Coverage - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 + uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5 with: name: lcov-vitest path: hivemq-edge-frontend/coverage-vitest/lcov.info @@ -60,7 +60,7 @@ jobs: runs-on: ubuntu-latest steps: - name: 👓 Checkout repository - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 + uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6 - name: 🏗️ Setup node environment uses: ./.github/actions/setup_node @@ -73,7 +73,7 @@ jobs: VITE_COVERAGE: true - name: Upload artifact - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 + uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5 with: name: application-instrumented path: ./hivemq-edge-frontend/dist @@ -84,7 +84,7 @@ jobs: runs-on: ubuntu-latest steps: - name: 👓 Checkout repository - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 + uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6 - name: 🏗️ Setup node environment uses: ./.github/actions/setup_node @@ -95,7 +95,7 @@ jobs: run: pnpm run build --base=/ - name: Upload artifact - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 + uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5 with: name: application-clean path: ./hivemq-edge-frontend/dist @@ -107,10 +107,10 @@ jobs: needs: [ build_production ] steps: - name: 👓 Checkout repository - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 + uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6 - name: Download artifact - uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4 + uses: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53 # v6 with: name: application-clean path: ./hivemq-edge-frontend/dist @@ -131,7 +131,7 @@ jobs: LOCAL_NONCE: ${{ steps.percy.outputs.nonce }} steps: - name: 👓 Checkout repository - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 + uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6 - id: percy run: | echo "nonce=$(date +'%s')" >> "$GITHUB_OUTPUT" @@ -168,7 +168,7 @@ jobs: name: Cypress - ${{ matrix.cypress.target }} steps: - name: 👓 Checkout repository - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 + uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6 - name: 🏗️ Setup node environment uses: ./.github/actions/setup_node @@ -177,7 +177,7 @@ jobs: run-install: true - name: Download artifact - uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4 + uses: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53 # v6 with: name: application-instrumented path: ./hivemq-edge-frontend/dist @@ -198,7 +198,7 @@ jobs: # after the test, store videos - name: 💾 Upload Cypress - ${{ matrix.cypress.target }} videos if: failure() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 + uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5 with: name: cypress-${{ matrix.cypress.target }}-videos path: hivemq-edge-frontend/cypress/videos @@ -207,7 +207,7 @@ jobs: - name: 💾 Upload Cypress Code Coverage if: success() || failure() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 + uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5 with: name: lcov-cypress-${{ matrix.cypress.target }} path: hivemq-edge-frontend/coverage-cypress/lcov.info @@ -222,11 +222,11 @@ jobs: runs-on: ubuntu-latest steps: - name: 👓 Checkout repository - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 + uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6 with: fetch-depth: 0 # Shallow clones should be disabled for a better relevancy of analysis - name: Download all LCOV Artifacts - uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4 + uses: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53 # v6 with: path: hivemq-edge-frontend/coverage-combined pattern: lcov-* @@ -237,7 +237,7 @@ jobs: ls -R ./coverage-combined ls -R **/**/*.info - name: SonarQube Scan - uses: SonarSource/sonarqube-scan-action@2500896589ef8f7247069a56136f8dc177c27ccf # v5 + uses: SonarSource/sonarqube-scan-action@fd88b7d7ccbaefd23d8f36f73b59db7a3d246602 # v6 with: projectBaseDir: hivemq-edge-frontend args: > @@ -256,7 +256,7 @@ jobs: PERCY_TOKEN: ${{ secrets.PERCY_TOKEN }} steps: - name: 👓 Checkout repository - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 + uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6 - name: 🏗️ Setup node environment uses: ./.github/actions/setup_node diff --git a/.github/workflows/check-openapi.yml b/.github/workflows/check-openapi.yml index fa068207da..a54496b796 100644 --- a/.github/workflows/check-openapi.yml +++ b/.github/workflows/check-openapi.yml @@ -14,7 +14,7 @@ jobs: runs-on: ubuntu-latest steps: - name: 👓 Checkout repository - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 + uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6 - name: 🏗️ Setup node environment uses: ./.github/actions/setup_node diff --git a/.github/workflows/check.yml b/.github/workflows/check.yml index 8f06c676b2..87ed4acf74 100644 --- a/.github/workflows/check.yml +++ b/.github/workflows/check.yml @@ -29,7 +29,7 @@ jobs: openapi-changed: ${{ steps.openapi.outputs.changed }} steps: - name: Checkout - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 + uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6 with: fetch-depth: 0 diff --git a/.github/workflows/etherip-package.yml b/.github/workflows/etherip-package.yml index 9092bc7823..29aa84c1fe 100644 --- a/.github/workflows/etherip-package.yml +++ b/.github/workflows/etherip-package.yml @@ -14,11 +14,11 @@ jobs: packages: write steps: - name: Checkout - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 + uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6 with: repository: 'ornl-epics/etherip' - name: Setup Java - uses: actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 # v4 + uses: actions/setup-java@f2beeb24e141e01a676f977032f5a29d81c9e27e # v5 with: distribution: 'adopt' java-version: '21' diff --git a/.github/workflows/snyk-pr.yml b/.github/workflows/snyk-pr.yml index 6aae1a29ff..ffca314408 100644 --- a/.github/workflows/snyk-pr.yml +++ b/.github/workflows/snyk-pr.yml @@ -18,7 +18,7 @@ jobs: steps: - name: Setup Java - uses: actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 # v4 + uses: actions/setup-java@f2beeb24e141e01a676f977032f5a29d81c9e27e # v5 with: distribution: 'temurin' java-version: | @@ -40,7 +40,7 @@ jobs: github-token: ${{ secrets.JENKINS_GITHUB_TOKEN }} - name: Setup Node.js - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 + uses: actions/setup-node@395ad3262231945c25e8478fd5baf05154b1d79f # v6.1.0 with: node-version: '20.13.1' diff --git a/.github/workflows/snyk-push.yml b/.github/workflows/snyk-push.yml index 0b1926af4b..42fa85c2a2 100644 --- a/.github/workflows/snyk-push.yml +++ b/.github/workflows/snyk-push.yml @@ -23,7 +23,7 @@ jobs: echo "selected_github_ref=${workflow_call_github_ref:-${{ github.ref_name }}}" >> "$GITHUB_OUTPUT" - name: Setup Java - uses: actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 # v4 + uses: actions/setup-java@f2beeb24e141e01a676f977032f5a29d81c9e27e # v5 with: distribution: 'temurin' java-version: | @@ -49,7 +49,7 @@ jobs: SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} - name: Setup Node.js - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 + uses: actions/setup-node@395ad3262231945c25e8478fd5baf05154b1d79f # v6.1.0 with: node-version: '20.13.1' diff --git a/.github/workflows/snyk-release.yml b/.github/workflows/snyk-release.yml index e25421df10..6c660ad3fb 100644 --- a/.github/workflows/snyk-release.yml +++ b/.github/workflows/snyk-release.yml @@ -11,7 +11,7 @@ jobs: steps: - name: Setup Java - uses: actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 # v4 + uses: actions/setup-java@f2beeb24e141e01a676f977032f5a29d81c9e27e # v5 with: distribution: 'temurin' java-version: | @@ -33,7 +33,7 @@ jobs: SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} - name: Setup Node.js - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 + uses: actions/setup-node@395ad3262231945c25e8478fd5baf05154b1d79f # v6.1.0 with: node-version: '20.13.1'