diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..2c48305 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,11 @@ +version: 2 +updates: + - package-ecosystem: "github-actions" + directory: "/" + groups: + github-actions: + patterns: ["*"] + schedule: + interval: "weekly" + cooldown: + default-days: 7 diff --git a/.github/workflows/bicep-audit.yml b/.github/workflows/bicep-audit.yml index 7ededd4..5d3e93d 100644 --- a/.github/workflows/bicep-audit.yml +++ b/.github/workflows/bicep-audit.yml @@ -19,10 +19,10 @@ jobs: security-events: write steps: - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 - name: Run PSRule analysis - uses: microsoft/ps-rule@v2.9.0 + uses: microsoft/ps-rule@46451b8f5258c41beb5ae69ed7190ccbba84112c # v2.9.0 with: modules: PSRule.Rules.Azure baseline: Azure.Pillar.Security @@ -37,7 +37,7 @@ jobs: PSRULE_CONFIGURATION_AZURE_BICEP_FILE_EXPANSION_TIMEOUT: '30' - name: Upload results to security tab - uses: github/codeql-action/upload-sarif@v3 + uses: github/codeql-action/upload-sarif@6f5948dfacef28e207b48d0905cf90c03365536d # v3.37.9 if: github.repository_owner == 'Azure-Samples' with: sarif_file: reports/ps-rule-results.sarif diff --git a/.github/workflows/dotnet.yml b/.github/workflows/dotnet.yml index 87d8df7..617c1cd 100644 --- a/.github/workflows/dotnet.yml +++ b/.github/workflows/dotnet.yml @@ -14,9 +14,9 @@ jobs: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v2 + - uses: actions/checkout@0717577d45739eb3c851188b29f50ed6c0b2194e # v2.8.0 - name: Setup .NET - uses: actions/setup-dotnet@v1 + uses: actions/setup-dotnet@871f041373faaad213a635d9afb62905ec029bbb # v1.10.1 with: dotnet-version: 6.0.x - name: Build, restore, test @@ -27,10 +27,10 @@ jobs: name: Build and Test for arm64 runs-on: ubuntu-20.04 steps: - - uses: actions/checkout@v2 + - uses: actions/checkout@0717577d45739eb3c851188b29f50ed6c0b2194e # v2.8.0 - name: Set up QEMU id: qemu - uses: docker/setup-qemu-action@v1 + uses: docker/setup-qemu-action@27d0a4f181a40b142cce983c5393082c365d1480 # v1.2.0 - name: Install and Run tests run: | docker run --rm -v ${{ github.workspace }}:/ws:rw --workdir=/ws \ diff --git a/.github/workflows/nodejs.yml b/.github/workflows/nodejs.yml index 4673016..5b4eed0 100644 --- a/.github/workflows/nodejs.yml +++ b/.github/workflows/nodejs.yml @@ -22,9 +22,9 @@ jobs: node-version: [14.x, 12.x, 10.x] steps: - - uses: actions/checkout@v2 + - uses: actions/checkout@0717577d45739eb3c851188b29f50ed6c0b2194e # v2.8.0 - name: Use Node.js ${{ matrix.node-version }} - uses: actions/setup-node@v2 + uses: actions/setup-node@7c12f8017d5436eb855f1ed4399f037a36fbd9e8 # v2.5.2 with: node-version: ${{ matrix.node-version }} cache: 'npm' @@ -36,10 +36,10 @@ jobs: name: Build and Test for arm64 runs-on: ubuntu-20.04 steps: - - uses: actions/checkout@v2 + - uses: actions/checkout@0717577d45739eb3c851188b29f50ed6c0b2194e # v2.8.0 - name: Set up QEMU id: qemu - uses: docker/setup-qemu-action@v1 + uses: docker/setup-qemu-action@27d0a4f181a40b142cce983c5393082c365d1480 # v1.2.0 - name: Install and Run tests run: | docker run --rm -v ${{ github.workspace }}:/ws:rw --workdir=/ws \ diff --git a/.github/workflows/spa.yml b/.github/workflows/spa.yml index f7f603e..4cdd2cd 100644 --- a/.github/workflows/spa.yml +++ b/.github/workflows/spa.yml @@ -22,9 +22,9 @@ jobs: node-version: [14.x, 12.x, 10.x] steps: - - uses: actions/checkout@v2 + - uses: actions/checkout@0717577d45739eb3c851188b29f50ed6c0b2194e # v2.8.0 - name: Use Node.js ${{ matrix.node-version }} - uses: actions/setup-node@v2 + uses: actions/setup-node@7c12f8017d5436eb855f1ed4399f037a36fbd9e8 # v2.5.2 with: node-version: ${{ matrix.node-version }} cache: 'npm' @@ -36,10 +36,10 @@ jobs: name: Build and Test for arm64 runs-on: ubuntu-20.04 steps: - - uses: actions/checkout@v2 + - uses: actions/checkout@0717577d45739eb3c851188b29f50ed6c0b2194e # v2.8.0 - name: Set up QEMU id: qemu - uses: docker/setup-qemu-action@v1 + uses: docker/setup-qemu-action@27d0a4f181a40b142cce983c5393082c365d1480 # v1.2.0 - name: Install and Run tests run: | docker run --rm -v ${{ github.workspace }}:/ws:rw --workdir=/ws \