diff --git a/.github/workflows/apply-repo-settings.yaml b/.github/workflows/apply-repo-settings.yaml index 009b704..96db741 100644 --- a/.github/workflows/apply-repo-settings.yaml +++ b/.github/workflows/apply-repo-settings.yaml @@ -53,14 +53,14 @@ jobs: steps: - name: Checkout as GitHub App id: checkout - uses: nsheaps/github-actions/.github/actions/checkout-as-app@c1794f6f4fbb3cbc5e5a71e820581a74239f706a # main + uses: nsheaps/github-actions/.github/actions/checkout-as-app@1e129396b6f0b39257efac9a255010fe64a68ef8 # main with: app-id: ${{ secrets.AUTOMATION_GITHUB_APP_ID }} private-key: ${{ secrets.AUTOMATION_GITHUB_APP_PRIVATE_KEY }} - name: Apply id: apply - uses: nsheaps/github-actions/.github/actions/apply-repo-settings@c1794f6f4fbb3cbc5e5a71e820581a74239f706a # main + uses: nsheaps/github-actions/.github/actions/apply-repo-settings@1e129396b6f0b39257efac9a255010fe64a68ef8 # main with: token: ${{ steps.checkout.outputs.token }} dry-run: ${{ inputs.dry-run || false }} diff --git a/.github/workflows/dispatch-review.yaml b/.github/workflows/dispatch-review.yaml index 7ec1437..f5f9a3a 100644 --- a/.github/workflows/dispatch-review.yaml +++ b/.github/workflows/dispatch-review.yaml @@ -65,7 +65,7 @@ jobs: # on the next PR event in repos using this template. This is intentional — # operators who need pinned stability should replace @main with a commit SHA # and update it in lock-step with plugin version bumps. - uses: nsheaps/agents/.github/workflows/review-dispatch.yaml@9384e01dd798d677750775d50068853aeb315b0b # main + uses: nsheaps/agents/.github/workflows/review-dispatch.yaml@e4304401a9b5dbb9b62cf6306168aec130f81d74 # main # secrets: inherit doesn't pass cross-repo (GitHub limitation). secrets: AUTOMATION_GITHUB_APP_ID: ${{ secrets.AUTOMATION_GITHUB_APP_ID }} diff --git a/.github/workflows/pr-status-dispatch.yaml b/.github/workflows/pr-status-dispatch.yaml index 2a6dc34..1c99946 100644 --- a/.github/workflows/pr-status-dispatch.yaml +++ b/.github/workflows/pr-status-dispatch.yaml @@ -41,7 +41,7 @@ jobs: steps: - name: Authenticate as GitHub App id: app-token - uses: nsheaps/github-actions/.github/actions/github-app-auth@c1794f6f4fbb3cbc5e5a71e820581a74239f706a # main + uses: nsheaps/github-actions/.github/actions/github-app-auth@1e129396b6f0b39257efac9a255010fe64a68ef8 # main with: app-id: ${{ secrets.AUTOMATION_GITHUB_APP_ID }} private-key: ${{ secrets.AUTOMATION_GITHUB_APP_PRIVATE_KEY }}