diff --git a/.github/workflows/conventional-commits.yml b/.github/workflows/conventional-commits.yml index 2a52538..cfd8d56 100644 --- a/.github/workflows/conventional-commits.yml +++ b/.github/workflows/conventional-commits.yml @@ -16,7 +16,7 @@ jobs: name: Validate PR title runs-on: ubuntu-24.04 steps: - - uses: amannn/action-semantic-pull-request@48f256284bd46cdaab1048c3721360e808335d50 # v6 + - uses: amannn/action-semantic-pull-request@48f256284bd46cdaab1048c3721360e808335d50 # v6.1.1 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} with: @@ -34,7 +34,7 @@ jobs: name: Validate commit messages runs-on: ubuntu-24.04 steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6 + - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 with: fetch-depth: 0 - uses: webiny/action-conventional-commits@7f91b1595ca1951cdb671ddc9f07a49081ec5b69 # v1.4.2 diff --git a/.github/workflows/copilot-setup-steps.yml b/.github/workflows/copilot-setup-steps.yml index c619c87..1cd2941 100644 --- a/.github/workflows/copilot-setup-steps.yml +++ b/.github/workflows/copilot-setup-steps.yml @@ -17,7 +17,7 @@ jobs: steps: - name: Checkout code - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6 + uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - name: Install pre-commit run: | diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index 65e2a29..82fc9ce 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -13,13 +13,13 @@ jobs: release-please: runs-on: ubuntu-24.04 steps: - - uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3 + - uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 id: app-token with: app-id: ${{ vars.RELEASE_PLEASE_APP_ID }} private-key: ${{ secrets.RELEASE_PLEASE_PRIVATE_KEY }} - name: Run release-please id: release - uses: googleapis/release-please-action@45996ed1f6d02564a971a2fa1b5860e934307cf7 # v5 + uses: googleapis/release-please-action@45996ed1f6d02564a971a2fa1b5860e934307cf7 # v5.0.0 with: token: ${{ steps.app-token.outputs.token }} diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index c84cacd..c76b8c1 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -25,7 +25,7 @@ jobs: runs-on: ubuntu-24.04 steps: - - uses: ddev/github-action-add-on-test@b6002da3c9c8168ce1f2f77ce009e5569597950e # v2 + - uses: ddev/github-action-add-on-test@b6002da3c9c8168ce1f2f77ce009e5569597950e # v2.4.4 with: ddev_version: ${{ matrix.ddev_version }} addon_repository: ${{ github.repository }} diff --git a/renovate.json b/renovate.json index aa3caf4..ece6fc4 100644 --- a/renovate.json +++ b/renovate.json @@ -2,7 +2,7 @@ "$schema": "https://docs.renovatebot.com/renovate-schema.json", "extends": [ "config:recommended", - "helpers:pinGitHubActionDigests" + "helpers:pinGitHubActionDigestsToSemver" ], "customManagers": [ { @@ -19,7 +19,9 @@ "minimumReleaseAge": "3 days", "packageRules": [ { - "matchManagers": ["github-actions"], + "description": "Never automerge a digest-only update: that is an existing action tag being repointed at a new commit, which needs a human to look at it.", + "matchDepTypes": ["action"], + "matchUpdateTypes": ["digest"], "automerge": false } ]