chore(deps): update github actions

This commit is contained in:
renovate[bot] 2026-08-24 21:05:53 +00:00 • committed by GitHub
parent cc75356ed1
commit 122292e109
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
28 changed files with 40 additions and 40 deletions

View file

@ -16,7 +16,7 @@ jobs:
dependency-review: dependency-review:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7.0.1
- uses: actions/dependency-review-action@v5 - uses: actions/dependency-review-action@v5
with: with:
fail-on-severity: high fail-on-severity: high

View file

@ -70,9 +70,9 @@ jobs:
group: cd-cdk-${{ inputs.region }}-${{ inputs.stacks }}-${{ inputs.stack-name }} group: cd-cdk-${{ inputs.region }}-${{ inputs.stacks }}-${{ inputs.stack-name }}
cancel-in-progress: false cancel-in-progress: false
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7.0.1
- uses: docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v4 - uses: docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v4.2.0
if: ${{ inputs.enable-qemu }} if: ${{ inputs.enable-qemu }}
- uses: actions/setup-dotnet@v6 - uses: actions/setup-dotnet@v6
@ -121,7 +121,7 @@ jobs:
pip install -r "$req" pip install -r "$req"
done < <(find . -name requirements.txt -not -path '*/node_modules/*' -print0) done < <(find . -name requirements.txt -not -path '*/node_modules/*' -print0)
- uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6 - uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3
with: with:
role-to-assume: ${{ secrets.deploy-role-arn }} role-to-assume: ${{ secrets.deploy-role-arn }}
aws-region: ${{ inputs.region }} aws-region: ${{ inputs.region }}

View file

@ -82,7 +82,7 @@ jobs:
run: run:
working-directory: ${{ inputs.working-directory }} working-directory: ${{ inputs.working-directory }}
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7.0.1
- uses: actions/setup-dotnet@v6 - uses: actions/setup-dotnet@v6
with: with:
@ -119,7 +119,7 @@ jobs:
cd .. cd ..
echo "Bundle size: $(du -h bundle.zip | cut -f1)" echo "Bundle size: $(du -h bundle.zip | cut -f1)"
- uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6 - uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3
with: with:
role-to-assume: ${{ secrets.deploy-role-arn }} role-to-assume: ${{ secrets.deploy-role-arn }}
aws-region: ${{ inputs.region }} aws-region: ${{ inputs.region }}

View file

@ -69,9 +69,9 @@ jobs:
run: run:
working-directory: ${{ inputs.working-directory }} working-directory: ${{ inputs.working-directory }}
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7.0.1
- uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6 - uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3
with: with:
role-to-assume: ${{ secrets.deploy-role-arn }} role-to-assume: ${{ secrets.deploy-role-arn }}
aws-region: ${{ inputs.region }} aws-region: ${{ inputs.region }}
@ -82,7 +82,7 @@ jobs:
cache: npm cache: npm
cache-dependency-path: ${{ inputs.cache-dependency-path }} cache-dependency-path: ${{ inputs.cache-dependency-path }}
- uses: ruby/setup-ruby@95ef2b042f9d7a56d8268cba8559e2842e2ad01b # v1 - uses: ruby/setup-ruby@95ef2b042f9d7a56d8268cba8559e2842e2ad01b # v1.321.0
with: with:
ruby-version: ${{ inputs.ruby-version }} ruby-version: ${{ inputs.ruby-version }}
bundler-cache: true bundler-cache: true

View file

@ -49,7 +49,7 @@ jobs:
group: cd-sam-${{ inputs.region }}-${{ inputs.stack-name }} group: cd-sam-${{ inputs.region }}-${{ inputs.stack-name }}
cancel-in-progress: false cancel-in-progress: false
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7.0.1
- uses: actions/setup-python@v7 - uses: actions/setup-python@v7
with: with:
@ -57,7 +57,7 @@ jobs:
- uses: aws-actions/setup-sam@89ddb14d60e682855e3fea4be85b3c56485de310 # v3 - uses: aws-actions/setup-sam@89ddb14d60e682855e3fea4be85b3c56485de310 # v3
- uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6 - uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3
with: with:
role-to-assume: ${{ secrets.deploy-role-arn }} role-to-assume: ${{ secrets.deploy-role-arn }}
aws-region: ${{ inputs.region }} aws-region: ${{ inputs.region }}

View file

@ -34,7 +34,7 @@ jobs:
run: run:
working-directory: ${{ inputs.working-directory }} working-directory: ${{ inputs.working-directory }}
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7.0.1
- uses: actions/setup-dotnet@v6 - uses: actions/setup-dotnet@v6
with: with:

View file

@ -137,7 +137,7 @@ jobs:
run: run:
working-directory: ${{ inputs.working-directory }} working-directory: ${{ inputs.working-directory }}
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7.0.1
- uses: actions/setup-node@v7 - uses: actions/setup-node@v7
with: with:
@ -206,7 +206,7 @@ jobs:
run: run:
working-directory: ${{ inputs.working-directory }} working-directory: ${{ inputs.working-directory }}
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7.0.1
- uses: actions/setup-node@v7 - uses: actions/setup-node@v7
with: with:
@ -214,7 +214,7 @@ jobs:
cache: npm cache: npm
cache-dependency-path: ${{ inputs.cache-dependency-path }} cache-dependency-path: ${{ inputs.cache-dependency-path }}
- uses: ruby/setup-ruby@95ef2b042f9d7a56d8268cba8559e2842e2ad01b # v1 - uses: ruby/setup-ruby@95ef2b042f9d7a56d8268cba8559e2842e2ad01b # v1.321.0
with: with:
ruby-version: ${{ inputs.ruby-version }} ruby-version: ${{ inputs.ruby-version }}
bundler-cache: true bundler-cache: true

View file

@ -60,7 +60,7 @@ jobs:
group: ci-python-app-${{ github.workflow }}-${{ github.ref }}-${{ inputs.source-dirs }}-lint group: ci-python-app-${{ github.workflow }}-${{ github.ref }}-${{ inputs.source-dirs }}-lint
cancel-in-progress: true cancel-in-progress: true
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7.0.1
- uses: actions/setup-python@v7 - uses: actions/setup-python@v7
with: with:
@ -109,7 +109,7 @@ jobs:
group: ci-python-app-${{ github.workflow }}-${{ github.ref }}-${{ inputs.source-dirs }}-test-collect group: ci-python-app-${{ github.workflow }}-${{ github.ref }}-${{ inputs.source-dirs }}-test-collect
cancel-in-progress: true cancel-in-progress: true
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7.0.1
- uses: actions/setup-python@v7 - uses: actions/setup-python@v7
with: with:
@ -133,7 +133,7 @@ jobs:
group: ci-python-app-${{ github.workflow }}-${{ github.ref }}-${{ inputs.source-dirs }}-subproject-tests group: ci-python-app-${{ github.workflow }}-${{ github.ref }}-${{ inputs.source-dirs }}-subproject-tests
cancel-in-progress: true cancel-in-progress: true
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7.0.1
- uses: actions/setup-python@v7 - uses: actions/setup-python@v7
with: with:

View file

@ -55,7 +55,7 @@ jobs:
group: ci-python-sam-${{ github.workflow }}-${{ github.ref }}-${{ inputs.source-dirs }} group: ci-python-sam-${{ github.workflow }}-${{ github.ref }}-${{ inputs.source-dirs }}
cancel-in-progress: true cancel-in-progress: true
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7.0.1
- uses: actions/setup-python@v7 - uses: actions/setup-python@v7
with: with:
@ -95,7 +95,7 @@ jobs:
- name: Set up QEMU - name: Set up QEMU
if: ${{ inputs.run-cdk-synth && inputs.enable-qemu }} if: ${{ inputs.run-cdk-synth && inputs.enable-qemu }}
uses: docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v4 uses: docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v4.2.0
- name: CDK synth - name: CDK synth
if: ${{ inputs.run-cdk-synth }} if: ${{ inputs.run-cdk-synth }}

View file

@ -70,7 +70,7 @@ jobs:
CHECK_DIR: ${{ inputs.check-dir }} CHECK_DIR: ${{ inputs.check-dir }}
BUILD_COMMAND: ${{ inputs.build-command }} BUILD_COMMAND: ${{ inputs.build-command }}
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7.0.1
- uses: actions/setup-node@v7 - uses: actions/setup-node@v7
if: ${{ inputs.run-htmlhint || inputs.build-command != '' }} if: ${{ inputs.run-htmlhint || inputs.build-command != '' }}

View file

@ -67,9 +67,9 @@ jobs:
group: ci-typescript-cdk-${{ github.workflow }}-${{ github.ref }}-${{ inputs.working-directory }} group: ci-typescript-cdk-${{ github.workflow }}-${{ github.ref }}-${{ inputs.working-directory }}
cancel-in-progress: true cancel-in-progress: true
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7.0.1
- uses: docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v4 - uses: docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v4.2.0
if: ${{ inputs.enable-qemu }} if: ${{ inputs.enable-qemu }}
- uses: actions/setup-dotnet@v6 - uses: actions/setup-dotnet@v6

View file

@ -87,7 +87,7 @@ jobs:
run: run:
working-directory: ${{ inputs.working-directory }} working-directory: ${{ inputs.working-directory }}
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7.0.1
with: with:
fetch-depth: 0 fetch-depth: 0

View file

@ -59,7 +59,7 @@ jobs:
outputs: outputs:
version: ${{ steps.next.outputs.version }} version: ${{ steps.next.outputs.version }}
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7.0.1
with: with:
# Tags are the input to the version calculation, so they must be # Tags are the input to the version calculation, so they must be
# fetched; a shallow checkout without them would restart at 1.0.0. # fetched; a shallow checkout without them would restart at 1.0.0.

View file

@ -118,7 +118,7 @@ jobs:
released: ${{ steps.publish.outputs.released || 'false' }} released: ${{ steps.publish.outputs.released || 'false' }}
url: ${{ steps.publish.outputs.url }} url: ${{ steps.publish.outputs.url }}
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7.0.1
with: with:
# Full history + tags: the existing-tag guard reads local refs. # Full history + tags: the existing-tag guard reads local refs.
fetch-depth: 0 fetch-depth: 0

View file

@ -5,7 +5,7 @@ on:
jobs: jobs:
deploy: deploy:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@af0f002e14a08cdbfd879c1183bfe7eb2604bce9 # v1.0.8
with: with:
# Matches local dev (Node 24 / npm 11, lockfileVersion 3). This is also the # Matches local dev (Node 24 / npm 11, lockfileVersion 3). This is also the
# reusable workflow's default — passed explicitly to pin against drift. # reusable workflow's default — passed explicitly to pin against drift.

View file

@ -12,4 +12,4 @@ jobs:
# Every input is optional. Common overrides: `solution` (defaults to *.sln # Every input is optional. Common overrides: `solution` (defaults to *.sln
# in the working directory), `working-directory`, and `dotnet-version` # in the working directory), `working-directory`, and `dotnet-version`
# (defaults to 8.0.x). This reusable has no `node-version` input. # (defaults to 8.0.x). This reusable has no `node-version` input.
uses: Sea-Haven-Industries/.github/.github/workflows/ci-dotnet.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 uses: Sea-Haven-Industries/.github/.github/workflows/ci-dotnet.yaml@af0f002e14a08cdbfd879c1183bfe7eb2604bce9 # v1.0.8

View file

@ -8,7 +8,7 @@ jobs:
ci: ci:
# Job id MUST stay `ci`: the reusable's aggregator job is also `ci`, so the # Job id MUST stay `ci`: the reusable's aggregator job is also `ci`, so the
# check context resolves to the required `ci / ci`. # check context resolves to the required `ci / ci`.
uses: Sea-Haven-Industries/.github/.github/workflows/ci-mobile-ios.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 uses: Sea-Haven-Industries/.github/.github/workflows/ci-mobile-ios.yaml@af0f002e14a08cdbfd879c1183bfe7eb2604bce9 # v1.0.8
with: with:
# Matches local dev (Node 24 / npm 11, lockfileVersion 3). This is also # Matches local dev (Node 24 / npm 11, lockfileVersion 3). This is also
# the reusable workflow's default — passed explicitly to pin against drift. # the reusable workflow's default — passed explicitly to pin against drift.

View file

@ -6,7 +6,7 @@ on:
jobs: jobs:
ci: ci:
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@af0f002e14a08cdbfd879c1183bfe7eb2604bce9 # v1.0.8
with: with:
# Matches local dev (Node 24 / npm 11, lockfileVersion 3). This is also the # Matches local dev (Node 24 / npm 11, lockfileVersion 3). This is also the
# reusable workflow's default — passed explicitly to pin against drift. # reusable workflow's default — passed explicitly to pin against drift.

View file

@ -12,4 +12,4 @@ jobs:
# Every input is optional. Common overrides: `source-dirs` (ruff targets), # Every input is optional. Common overrides: `source-dirs` (ruff targets),
# `requirements` (non-default requirements file), `subproject-dir` (a # `requirements` (non-default requirements file), `subproject-dir` (a
# self-contained suite that must run in its own working directory). # self-contained suite that must run in its own working directory).
uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml@af0f002e14a08cdbfd879c1183bfe7eb2604bce9 # v1.0.8

View file

@ -6,7 +6,7 @@ on:
jobs: jobs:
ci: ci:
uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@af0f002e14a08cdbfd879c1183bfe7eb2604bce9 # v1.0.8
with: with:
run-tests: true run-tests: true
# ci-python-sam.yaml declares a `node-version` input (default "24") that # ci-python-sam.yaml declares a `node-version` input (default "24") that

View file

@ -8,7 +8,7 @@ jobs:
ci: ci:
# Job id MUST stay `ci`: the reusable's job is also `ci`, so the check # Job id MUST stay `ci`: the reusable's job is also `ci`, so the check
# context resolves to the required `ci / ci`. # context resolves to the required `ci / ci`.
uses: Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 uses: Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml@af0f002e14a08cdbfd879c1183bfe7eb2604bce9 # v1.0.8
with: with:
# Pinned explicitly (handbook): local dev is Node 24 / npm 11, which # Pinned explicitly (handbook): local dev is Node 24 / npm 11, which
# generates lockfileVersion 3. Being explicit avoids lockfile drift. # generates lockfileVersion 3. Being explicit avoids lockfile drift.

View file

@ -8,7 +8,7 @@ jobs:
ci: ci:
# Job id MUST stay `ci`: the reusable's job is also `ci`, so the check # Job id MUST stay `ci`: the reusable's job is also `ci`, so the check
# context resolves to the required `ci / ci`. # context resolves to the required `ci / ci`.
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-frontend.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-frontend.yaml@af0f002e14a08cdbfd879c1183bfe7eb2604bce9 # v1.0.8
with: with:
# Pinned explicitly (handbook): local dev is Node 24 / npm 11, which # Pinned explicitly (handbook): local dev is Node 24 / npm 11, which
# generates lockfileVersion 3. Being explicit avoids lockfile drift. # generates lockfileVersion 3. Being explicit avoids lockfile drift.

View file

@ -8,4 +8,4 @@ permissions:
jobs: jobs:
dependency-review: dependency-review:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@af0f002e14a08cdbfd879c1183bfe7eb2604bce9 # v1.0.8

View file

@ -5,7 +5,7 @@ on:
jobs: jobs:
deploy: deploy:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-dotnet-eb.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 uses: Sea-Haven-Industries/.github/.github/workflows/cd-dotnet-eb.yaml@af0f002e14a08cdbfd879c1183bfe7eb2604bce9 # v1.0.8
with: with:
# Required: the project to publish, relative to the repo root. # Required: the project to publish, relative to the repo root.
project: REPLACE-ME-project-csproj project: REPLACE-ME-project-csproj

View file

@ -13,4 +13,4 @@ permissions:
jobs: jobs:
label: label:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 uses: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml@af0f002e14a08cdbfd879c1183bfe7eb2604bce9 # v1.0.8

View file

@ -5,7 +5,7 @@ on:
jobs: jobs:
deploy: deploy:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-mobile-ios.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 uses: Sea-Haven-Industries/.github/.github/workflows/cd-mobile-ios.yaml@af0f002e14a08cdbfd879c1183bfe7eb2604bce9 # v1.0.8
with: with:
# Pinned explicitly (handbook): local dev is Node 24 / npm 11, which # Pinned explicitly (handbook): local dev is Node 24 / npm 11, which
# generates lockfileVersion 3. Being explicit avoids lockfile drift. # generates lockfileVersion 3. Being explicit avoids lockfile drift.

View file

@ -13,7 +13,7 @@ permissions:
jobs: jobs:
release: release:
uses: Sea-Haven-Industries/.github/.github/workflows/release.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 uses: Sea-Haven-Industries/.github/.github/workflows/release.yaml@af0f002e14a08cdbfd879c1183bfe7eb2604bce9 # v1.0.8
with: with:
version: ${{ inputs.version }} version: ${{ inputs.version }}
# Tags in this org are v-prefixed MAJOR.MINOR.PATCH; "v" is the default # Tags in this org are v-prefixed MAJOR.MINOR.PATCH; "v" is the default

View file

@ -5,7 +5,7 @@ on:
jobs: jobs:
deploy: deploy:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-sam.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 uses: Sea-Haven-Industries/.github/.github/workflows/cd-sam.yaml@af0f002e14a08cdbfd879c1183bfe7eb2604bce9 # v1.0.8
with: with:
# Required: the CloudFormation stack name (kebab-case, matches repo name). # Required: the CloudFormation stack name (kebab-case, matches repo name).
# NOTE: this is a literal placeholder on purpose — starter-workflow variables # NOTE: this is a literal placeholder on purpose — starter-workflow variables