diff --git a/.github/workflows/cd-hcp-fargate.yaml b/.github/workflows/cd-hcp-fargate.yaml index b4c6c55..8e90bba 100644 --- a/.github/workflows/cd-hcp-fargate.yaml +++ b/.github/workflows/cd-hcp-fargate.yaml @@ -216,7 +216,7 @@ jobs: echo "ship-gate: hotfix/release path accepted (${PREV} -> ${TAG} from ${TARGET_COMMITISH:-branch})" - name: Configure AWS credentials using OIDC - uses: aws-actions/configure-aws-credentials@cbe3b392738ccf3f987d68400dafcf4b0624a56c # v6.2.4 + uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0 with: role-to-assume: ${{ env.DEPLOY_ROLE_ARN }} aws-region: us-east-1 @@ -255,10 +255,10 @@ jobs: } >> "${GITHUB_OUTPUT}" - name: Set up QEMU - uses: docker/setup-qemu-action@1f40c72289eff860ee54a304f1438e3cff362e0a # v4.3.0 + uses: docker/setup-qemu-action@99012661954931238ded8c8b007157a8430204e1 # v4.4.0 - name: Set up Docker Buildx - uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1 + uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0 - name: Login to Amazon ECR uses: aws-actions/amazon-ecr-login@03f1aad4c6c7ffd436567f42f9384779290529bd # v2.1.7 diff --git a/.github/workflows/cd-hcp-lambda.yaml b/.github/workflows/cd-hcp-lambda.yaml index aaa5e65..c731ef3 100644 --- a/.github/workflows/cd-hcp-lambda.yaml +++ b/.github/workflows/cd-hcp-lambda.yaml @@ -244,7 +244,7 @@ jobs: PY - name: Configure AWS credentials using OIDC - uses: aws-actions/configure-aws-credentials@cbe3b392738ccf3f987d68400dafcf4b0624a56c # v6.2.4 + uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0 with: role-to-assume: ${{ env.DEPLOY_ROLE_ARN }} aws-region: us-east-1 diff --git a/.github/workflows/cd-hcp-spa.yaml b/.github/workflows/cd-hcp-spa.yaml index 9e7457d..b8f6ea3 100644 --- a/.github/workflows/cd-hcp-spa.yaml +++ b/.github/workflows/cd-hcp-spa.yaml @@ -225,7 +225,7 @@ jobs: echo "dist/index.html sha256=${index_sha}" - name: Configure AWS credentials using OIDC - uses: aws-actions/configure-aws-credentials@cbe3b392738ccf3f987d68400dafcf4b0624a56c # v6.2.4 + uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0 with: role-to-assume: ${{ env.DEPLOY_ROLE_ARN }} aws-region: us-east-1 diff --git a/.github/workflows/cd-hcp-static.yaml b/.github/workflows/cd-hcp-static.yaml index 2be4b71..bfaaa91 100644 --- a/.github/workflows/cd-hcp-static.yaml +++ b/.github/workflows/cd-hcp-static.yaml @@ -295,7 +295,7 @@ jobs: echo "${OUTPUT_DIR}/${VERIFY_KEY} sha256=${verify_sha}" - name: Configure AWS credentials using OIDC - uses: aws-actions/configure-aws-credentials@cbe3b392738ccf3f987d68400dafcf4b0624a56c # v6.2.4 + uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0 with: role-to-assume: ${{ env.DEPLOY_ROLE_ARN }} aws-region: us-east-1 diff --git a/.github/workflows/cd-mobile-ios.yaml b/.github/workflows/cd-mobile-ios.yaml index dbee35a..22ea116 100644 --- a/.github/workflows/cd-mobile-ios.yaml +++ b/.github/workflows/cd-mobile-ios.yaml @@ -82,7 +82,7 @@ jobs: cache: npm cache-dependency-path: ${{ inputs.cache-dependency-path }} - - uses: ruby/setup-ruby@a0102e0972be65f351c307e2d64b9314a57c8073 # v1.324.0 + - uses: ruby/setup-ruby@14594264cd68ce8a2345dd349bc3d138a4ef85c8 # v1.327.0 with: ruby-version: ${{ inputs.ruby-version }} bundler-cache: true diff --git a/.github/workflows/ci-mobile-ios.yaml b/.github/workflows/ci-mobile-ios.yaml index 6712e31..5aa4c50 100644 --- a/.github/workflows/ci-mobile-ios.yaml +++ b/.github/workflows/ci-mobile-ios.yaml @@ -214,7 +214,7 @@ jobs: cache: npm cache-dependency-path: ${{ inputs.cache-dependency-path }} - - uses: ruby/setup-ruby@a0102e0972be65f351c307e2d64b9314a57c8073 # v1.324.0 + - uses: ruby/setup-ruby@14594264cd68ce8a2345dd349bc3d138a4ef85c8 # v1.327.0 with: ruby-version: ${{ inputs.ruby-version }} bundler-cache: true diff --git a/workflow-templates/cdk-deploy.yml b/workflow-templates/cdk-deploy.yml index 0bab2cc..f24b07c 100644 --- a/workflow-templates/cdk-deploy.yml +++ b/workflow-templates/cdk-deploy.yml @@ -5,7 +5,7 @@ on: jobs: deploy: - uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@9781774f04b824b1182ff41638687f1c01c04361 # v1.0.11 + uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21 with: # Matches local dev (Node 24 / npm 11, lockfileVersion 3). This is also the # reusable workflow's default — passed explicitly to pin against drift. diff --git a/workflow-templates/ci-dotnet.yml b/workflow-templates/ci-dotnet.yml index 64eb84c..e2e79f3 100644 --- a/workflow-templates/ci-dotnet.yml +++ b/workflow-templates/ci-dotnet.yml @@ -12,4 +12,4 @@ jobs: # Every input is optional. Common overrides: `solution` (defaults to *.sln # in the working directory), `working-directory`, and `dotnet-version` # (defaults to 8.0.x). This reusable has no `node-version` input. - uses: Sea-Haven-Industries/.github/.github/workflows/ci-dotnet.yaml@9781774f04b824b1182ff41638687f1c01c04361 # v1.0.11 + uses: Sea-Haven-Industries/.github/.github/workflows/ci-dotnet.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21 diff --git a/workflow-templates/ci-mobile-ios.yml b/workflow-templates/ci-mobile-ios.yml index 67e883a..29ec974 100644 --- a/workflow-templates/ci-mobile-ios.yml +++ b/workflow-templates/ci-mobile-ios.yml @@ -8,7 +8,7 @@ jobs: ci: # Job id MUST stay `ci`: the reusable's aggregator job is also `ci`, so the # check context resolves to the required `ci / ci`. - uses: Sea-Haven-Industries/.github/.github/workflows/ci-mobile-ios.yaml@9781774f04b824b1182ff41638687f1c01c04361 # v1.0.11 + uses: Sea-Haven-Industries/.github/.github/workflows/ci-mobile-ios.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21 with: # Matches local dev (Node 24 / npm 11, lockfileVersion 3). This is also # the reusable workflow's default — passed explicitly to pin against drift. diff --git a/workflow-templates/ci-node.yml b/workflow-templates/ci-node.yml index 2448f0b..5e80b2c 100644 --- a/workflow-templates/ci-node.yml +++ b/workflow-templates/ci-node.yml @@ -6,7 +6,7 @@ on: jobs: ci: - uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@9781774f04b824b1182ff41638687f1c01c04361 # v1.0.11 + uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21 with: # Matches local dev (Node 24 / npm 11, lockfileVersion 3). This is also the # reusable workflow's default — passed explicitly to pin against drift. diff --git a/workflow-templates/ci-python-app.yml b/workflow-templates/ci-python-app.yml index 9c7cfd1..3a6a2fb 100644 --- a/workflow-templates/ci-python-app.yml +++ b/workflow-templates/ci-python-app.yml @@ -10,4 +10,4 @@ jobs: # check context resolves to the required `ci / ci`. # # Every input is optional. Common override: `source-dirs` (ruff targets). - uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml@9781774f04b824b1182ff41638687f1c01c04361 # v1.0.11 + uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21 diff --git a/workflow-templates/ci-python.yml b/workflow-templates/ci-python.yml index 93c7b4e..68bafe3 100644 --- a/workflow-templates/ci-python.yml +++ b/workflow-templates/ci-python.yml @@ -6,7 +6,7 @@ on: jobs: ci: - uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@9781774f04b824b1182ff41638687f1c01c04361 # v1.0.11 + uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21 with: run-tests: true # ci-python-sam.yaml declares a `node-version` input (default "24") that diff --git a/workflow-templates/ci-static.yml b/workflow-templates/ci-static.yml index 95eb033..5809cee 100644 --- a/workflow-templates/ci-static.yml +++ b/workflow-templates/ci-static.yml @@ -8,7 +8,7 @@ jobs: ci: # Job id MUST stay `ci`: the reusable's job is also `ci`, so the check # context resolves to the required `ci / ci`. - uses: Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml@9781774f04b824b1182ff41638687f1c01c04361 # v1.0.11 + uses: Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21 with: # Pinned explicitly (handbook): local dev is Node 24 / npm 11, which # generates lockfileVersion 3. Being explicit avoids lockfile drift. diff --git a/workflow-templates/ci-typescript-frontend.yml b/workflow-templates/ci-typescript-frontend.yml index 52b6e82..78cd754 100644 --- a/workflow-templates/ci-typescript-frontend.yml +++ b/workflow-templates/ci-typescript-frontend.yml @@ -8,7 +8,7 @@ jobs: ci: # Job id MUST stay `ci`: the reusable's job is also `ci`, so the check # context resolves to the required `ci / ci`. - uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-frontend.yaml@9781774f04b824b1182ff41638687f1c01c04361 # v1.0.11 + uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-frontend.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21 with: # Pinned explicitly (handbook): local dev is Node 24 / npm 11, which # generates lockfileVersion 3. Being explicit avoids lockfile drift. diff --git a/workflow-templates/dependency-review.yml b/workflow-templates/dependency-review.yml index 35a141e..f3dd282 100644 --- a/workflow-templates/dependency-review.yml +++ b/workflow-templates/dependency-review.yml @@ -8,4 +8,4 @@ permissions: jobs: dependency-review: - uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@9781774f04b824b1182ff41638687f1c01c04361 # v1.0.11 + uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21 diff --git a/workflow-templates/dotnet-eb-deploy.yml b/workflow-templates/dotnet-eb-deploy.yml index 779f9c5..2281d33 100644 --- a/workflow-templates/dotnet-eb-deploy.yml +++ b/workflow-templates/dotnet-eb-deploy.yml @@ -5,7 +5,7 @@ on: jobs: deploy: - uses: Sea-Haven-Industries/.github/.github/workflows/cd-dotnet-eb.yaml@9781774f04b824b1182ff41638687f1c01c04361 # v1.0.11 + uses: Sea-Haven-Industries/.github/.github/workflows/cd-dotnet-eb.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21 with: # Required: the project to publish, relative to the repo root. project: REPLACE-ME-project-csproj diff --git a/workflow-templates/labeler.yml b/workflow-templates/labeler.yml index 2846103..531ece9 100644 --- a/workflow-templates/labeler.yml +++ b/workflow-templates/labeler.yml @@ -13,4 +13,4 @@ permissions: jobs: label: - uses: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml@9781774f04b824b1182ff41638687f1c01c04361 # v1.0.11 + uses: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21 diff --git a/workflow-templates/mobile-ios-deploy.yml b/workflow-templates/mobile-ios-deploy.yml index face70c..f23f1b8 100644 --- a/workflow-templates/mobile-ios-deploy.yml +++ b/workflow-templates/mobile-ios-deploy.yml @@ -5,7 +5,7 @@ on: jobs: deploy: - uses: Sea-Haven-Industries/.github/.github/workflows/cd-mobile-ios.yaml@9781774f04b824b1182ff41638687f1c01c04361 # v1.0.11 + uses: Sea-Haven-Industries/.github/.github/workflows/cd-mobile-ios.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21 with: # Pinned explicitly (handbook): local dev is Node 24 / npm 11, which # generates lockfileVersion 3. Being explicit avoids lockfile drift. diff --git a/workflow-templates/release.yml b/workflow-templates/release.yml index ee27816..6464a13 100644 --- a/workflow-templates/release.yml +++ b/workflow-templates/release.yml @@ -13,7 +13,7 @@ permissions: jobs: release: - uses: Sea-Haven-Industries/.github/.github/workflows/release.yaml@9781774f04b824b1182ff41638687f1c01c04361 # v1.0.11 + uses: Sea-Haven-Industries/.github/.github/workflows/release.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21 with: version: ${{ inputs.version }} # Tags in this org are v-prefixed MAJOR.MINOR.PATCH; "v" is the default diff --git a/workflow-templates/sam-deploy.yml b/workflow-templates/sam-deploy.yml index a7a310d..1e0064b 100644 --- a/workflow-templates/sam-deploy.yml +++ b/workflow-templates/sam-deploy.yml @@ -5,7 +5,7 @@ on: jobs: deploy: - uses: Sea-Haven-Industries/.github/.github/workflows/cd-sam.yaml@9781774f04b824b1182ff41638687f1c01c04361 # v1.0.11 + uses: Sea-Haven-Industries/.github/.github/workflows/cd-sam.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21 with: # Required: the CloudFormation stack name (kebab-case, matches repo name). # NOTE: this is a literal placeholder on purpose — starter-workflow variables