diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index c7c883c..f8b6319 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -91,7 +91,7 @@ jobs: # JavaToolchainService (for -I$jdkHome/include -> jni.h), so a JRE would not do. - name: Set up Gradle (with dependency + build cache) - uses: gradle/actions/setup-gradle@9c971963bec38e04b3d30dcc455b5382be2fdbfb # v6.3.0 + uses: gradle/actions/setup-gradle@3f5f9adaf7d9fecd50b5935e54106014257a94e6 # v6.4.0 with: # Defense in depth on top of the SHA pin above: even a compromised action running # under this exact pinned commit could still try to poison the Gradle @@ -227,7 +227,7 @@ jobs: java-version: '21' - name: Set up Gradle (with dependency + build cache) - uses: gradle/actions/setup-gradle@9c971963bec38e04b3d30dcc455b5382be2fdbfb # v6.3.0 + uses: gradle/actions/setup-gradle@3f5f9adaf7d9fecd50b5935e54106014257a94e6 # v6.4.0 with: # See the identical comment on job 'build''s setup-gradle step: defense in depth # against cache poisoning surviving beyond a single (even correctly SHA-pinned)