File tree 8 files changed +12
-12
lines changed
8 files changed +12
-12
lines changed Original file line number Diff line number Diff line change @@ -9,11 +9,11 @@ inputs:
9
9
runs :
10
10
using : composite
11
11
steps :
12
- - uses : actions/cache@1bd1e32a3bdc45362d1e726936510720a7c30a57 # v4.2.0
12
+ - uses : actions/cache@0c907a75c2c80ebcb7f088228285e798b750cf8f # v4.2.1
13
13
with :
14
14
path : ~/go/pkg/mod
15
15
key : ${{ runner.os }}-go-pkg-mod-${{ hashFiles('**/go.sum') }}-${{ hashFiles('Makefile') }}
16
- - uses : actions/cache@1bd1e32a3bdc45362d1e726936510720a7c30a57 # v4.2.0
16
+ - uses : actions/cache@0c907a75c2c80ebcb7f088228285e798b750cf8f # v4.2.1
17
17
if : ${{ inputs.build-cache-key }}
18
18
with :
19
19
path : ~/.cache/go-build
Original file line number Diff line number Diff line change 17
17
- name : Checkout
18
18
uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
19
19
- name : Ensure SHA pinned actions
20
- uses : zgosalvez/github-actions-ensure-sha-pinned-actions@6eb1abde32fed00453b0d03497f4ba4fecba146d # v3.0.21
20
+ uses : zgosalvez/github-actions-ensure-sha-pinned-actions@25ed13d0628a1601b4b44048e63cc4328ed03633 # v3.0.22
21
21
with :
22
22
# slsa-github-generator requires using a semver tag for reusable workflows.
23
23
# See: https://github.com/slsa-framework/slsa-github-generator#referencing-slsa-builders-and-generators
Original file line number Diff line number Diff line change 52
52
with :
53
53
go-version-file : ' go.mod'
54
54
- name : Run Gosec Security Scanner
55
- uses : securego/gosec@e0cca6fe95306b7e7790d6f1bf6a7bec6d622459 # v2.22.0
55
+ uses : securego/gosec@43fee884f668c23601e0bec7a8c095fba226f889 # v2.22.1
56
56
with :
57
57
args : ' -no-fail -fmt sarif -out gosec.sarif ./...'
58
58
- name : Upload SARIF file
Original file line number Diff line number Diff line change 36
36
output : ' trivy-results.sarif'
37
37
severity : ' CRITICAL,HIGH'
38
38
- name : Install Cosign
39
- uses : sigstore/cosign-installer@c56c2d3e59e4281cc41dea2217323ba5694b171e # v3.8.0
39
+ uses : sigstore/cosign-installer@d7d6bc7722e3daa8354c50bcb52f4837da5e9b6a # v3.8.1
40
40
- name : Publish Capsule
41
41
id : publish-capsule
42
42
uses : peak-scale/github-actions/make-ko-publish@a441cca016861c546ab7e065277e40ce41a3eb84 # v0.2.0
Original file line number Diff line number Diff line change 45
45
chart-digest : ${{ steps.helm_publish.outputs.digest }}
46
46
steps :
47
47
- uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
48
- - uses : sigstore/cosign-installer@c56c2d3e59e4281cc41dea2217323ba5694b171e # v3.8.0
48
+ - uses : sigstore/cosign-installer@d7d6bc7722e3daa8354c50bcb52f4837da5e9b6a # v3.8.1
49
49
- name : " Extract Version"
50
50
id : extract_version
51
51
run : |
Original file line number Diff line number Diff line change 28
28
- uses : creekorful/goreportcard-action@1f35ced8cdac2cba28c9a2f2288a16aacfd507f9 # v1.0
29
29
- uses : anchore/sbom-action/download-syft@79202aee38a39bd2039be442e58d731b63baf740
30
30
- name : Install Cosign
31
- uses : sigstore/cosign-installer@c56c2d3e59e4281cc41dea2217323ba5694b171e # v3.8.0
31
+ uses : sigstore/cosign-installer@d7d6bc7722e3daa8354c50bcb52f4837da5e9b6a # v3.8.1
32
32
- name : Run GoReleaser
33
- uses : goreleaser/goreleaser-action@9ed2f89a662bf1735a48bc8557fd212fa902bebf # v6.1.0
33
+ uses : goreleaser/goreleaser-action@90a3faa9d0182683851fbfa97ca1a2cb983bfca3 # v6.2.1
34
34
with :
35
35
version : latest
36
36
args : release --clean --timeout 90m
Original file line number Diff line number Diff line change @@ -24,19 +24,19 @@ jobs:
24
24
with :
25
25
persist-credentials : false
26
26
- name : Run analysis
27
- uses : ossf/scorecard-action@62b2cac7ed8198b15735ed49ab1e5cf35480ba46 # v2.4.0
27
+ uses : ossf/scorecard-action@f49aabe0b5af0936a0987cfb85d86b75731b0186 # v2.4.1
28
28
with :
29
29
results_file : results.sarif
30
30
results_format : sarif
31
31
repo_token : ${{ secrets.SCORECARD_READ_TOKEN }}
32
32
publish_results : true
33
33
- name : Upload artifact
34
- uses : actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
34
+ uses : actions/upload-artifact@4cec3d8aa04e39d1a68397de0c4cd6fb9dce8ec1 # v4.6.1
35
35
with :
36
36
name : SARIF file
37
37
path : results.sarif
38
38
retention-days : 5
39
39
- name : Upload to code-scanning
40
- uses : github/codeql-action/upload-sarif@9e8d0789d4a0fa9ceb6b1738f7e269594bdd67f0 # v3.28.9
40
+ uses : github/codeql-action/upload-sarif@b56ba49b26e50535fa1e7f7db0f4f7b4bf65d80d # v3.28.10
41
41
with :
42
42
sarif_file : results.sarif
Original file line number Diff line number Diff line change 19
19
chart :
20
20
spec :
21
21
chart : capsule
22
- version : " 0.7.3 "
22
+ version : " 0.7.4 "
23
23
sourceRef :
24
24
kind : HelmRepository
25
25
name : projectcapsule
You can’t perform that action at this time.
0 commit comments