diff --git a/gyp/.github/dependabot.yml b/gyp/.github/dependabot.yml index 58d68276fc..1a5cdb30bd 100644 --- a/gyp/.github/dependabot.yml +++ b/gyp/.github/dependabot.yml @@ -10,6 +10,8 @@ updates: - "*" # Group all Actions updates into a single larger pull request schedule: interval: weekly + cooldown: + default-days: 7 - package-ecosystem: "pip" directory: "/" groups: @@ -18,3 +20,5 @@ updates: - "*" # Group all pip updates into a single larger pull request schedule: interval: weekly + cooldown: + default-days: 7 diff --git a/gyp/.github/workflows/node-gyp.yml b/gyp/.github/workflows/node-gyp.yml index e38d9c8fa2..cc7d4bf3f1 100644 --- a/gyp/.github/workflows/node-gyp.yml +++ b/gyp/.github/workflows/node-gyp.yml @@ -29,6 +29,7 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: path: gyp-next + persist-credentials: false - name: Clone nodejs/node-gyp uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: diff --git a/gyp/.github/workflows/nodejs.yml b/gyp/.github/workflows/nodejs.yml index 12849c809d..aecdfce173 100644 --- a/gyp/.github/workflows/nodejs.yml +++ b/gyp/.github/workflows/nodejs.yml @@ -27,6 +27,7 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: path: gyp-next + persist-credentials: false - name: Clone nodejs/node uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: diff --git a/gyp/.github/workflows/python_tests.yml b/gyp/.github/workflows/python_tests.yml index d73c6121c1..ab673bd3cf 100644 --- a/gyp/.github/workflows/python_tests.yml +++ b/gyp/.github/workflows/python_tests.yml @@ -16,7 +16,7 @@ jobs: - name: Lint with ruff # See pyproject.toml for settings uses: astral-sh/ruff-action@278981a28ce3188b1e39527901f38254bf3aac89 # v4.1.0 - run: ruff format --check --diff - - uses: wagoid/commitlint-github-action@v6 + - uses: wagoid/commitlint-github-action@b948419dd99f3fd78a6548d48f94e3df7f6bf3ed # v6.2.1 Python_tests: runs-on: ${{ matrix.os }} @@ -43,7 +43,7 @@ jobs: with: python-version: ${{ matrix.python-version }} allow-prereleases: true - - uses: seanmiddleditch/gha-setup-ninja@v6 + - uses: seanmiddleditch/gha-setup-ninja@3b1f8f94a2f8254bd26914c4ab9474d4f0015f67 # v6 - name: Install dependencies run: | python -m pip install --upgrade pip diff --git a/gyp/.github/workflows/release-please.yml b/gyp/.github/workflows/release-please.yml index 7e3b2e8f08..92138f14b0 100644 --- a/gyp/.github/workflows/release-please.yml +++ b/gyp/.github/workflows/release-please.yml @@ -16,7 +16,7 @@ jobs: contents: write pull-requests: write steps: - - uses: google-github-actions/release-please-action@v4 + - uses: google-github-actions/release-please-action@e4dc86ba9405554aeba3c6bb2d169500e7d3b4ee # v4.1.1 id: release build: @@ -32,7 +32,7 @@ jobs: - name: Build a binary wheel and a source tarball run: pipx run build - name: Store the distribution packages - uses: actions/upload-artifact@v7 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: python-package-distributions path: dist/ @@ -52,12 +52,12 @@ jobs: id-token: write # IMPORTANT: mandatory for trusted publishing steps: - name: Download all the dists - uses: actions/download-artifact@v8 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: python-package-distributions path: dist/ - name: Publish distribution to PyPI - uses: pypa/gh-action-pypi-publish@release/v1 + uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1.14.2 github-release: name: >- @@ -72,7 +72,7 @@ jobs: id-token: write # IMPORTANT: mandatory for sigstore steps: - name: Download all the dists - uses: actions/download-artifact@v8 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: python-package-distributions path: dist/