diff --git a/.github/actions/ai-pr-review/action.yml b/.github/actions/ai-pr-review/action.yml index abbdc33c..d3f1ec4b 100644 --- a/.github/actions/ai-pr-review/action.yml +++ b/.github/actions/ai-pr-review/action.yml @@ -95,7 +95,7 @@ runs: - name: Claude PR review if: steps.cfg.outputs.proceed == 'true' && inputs.provider == 'anthropic' - uses: anthropics/claude-code-action@8cf3482550831fb35a4fc3fbf7ca139cf8028b4c # v1.0.233 + uses: anthropics/claude-code-action@2dca132ff0e0c4094ce6048b422c6915a071210b # v1.0.247 with: anthropic_api_key: ${{ inputs.anthropic-api-key }} # zizmor: ignore[secrets-outside-env] -- API key passed via composite input, not a repo secret github_token: ${{ inputs.github-token }} @@ -144,7 +144,7 @@ runs: - name: Codex PR review id: codex if: steps.cfg.outputs.proceed == 'true' && inputs.provider == 'openai' - uses: openai/codex-action@86365089eb2b84e0a8fb0717b304f8bdcb13b20e # v1.12 + uses: openai/codex-action@bdf19a4a223ec2549a3e2274a0cf61556bc07675 # v1.13 with: openai-api-key: ${{ inputs.openai-api-key }} # zizmor: ignore[secrets-outside-env] -- API key passed via composite input, not a repo secret model: ${{ steps.cfg.outputs.model }} diff --git a/.github/actions/govulncheck/action.yml b/.github/actions/govulncheck/action.yml index 7c391af5..2e52b282 100644 --- a/.github/actions/govulncheck/action.yml +++ b/.github/actions/govulncheck/action.yml @@ -88,7 +88,7 @@ runs: steps.govulncheck.conclusion == 'failure' && inputs.notify == 'true' && github.event_name == 'schedule' - uses: loft-sh/github-actions/.github/actions/ci-test-notify@c6a76f19cc302d63d1631853496bce5bf76a4e0a # ci-test-notify/v1 + uses: loft-sh/github-actions/.github/actions/ci-test-notify@d15a1df8ea70c58cf70343f7c3687a6014ed63f8 # ci-test-notify/v1 with: test-name: ${{ inputs.test-name }} status: failure diff --git a/.github/actions/prerelease-setup/action.yml b/.github/actions/prerelease-setup/action.yml index f585ca17..b5cda3a9 100644 --- a/.github/actions/prerelease-setup/action.yml +++ b/.github/actions/prerelease-setup/action.yml @@ -62,7 +62,7 @@ runs: cache: true - name: Setup kubectl - uses: azure/setup-kubectl@829323503d1be3d00ca8346e5391ca0b07a9ab0d # v5.1.0 + uses: azure/setup-kubectl@bda439f5f36b99b262ebdcd3613869bddb064c8e # v5.2.0 - name: Setup helm uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5.0.1 diff --git a/.github/workflows/actionlint.yaml b/.github/workflows/actionlint.yaml index 5a73459a..df2bbdda 100644 --- a/.github/workflows/actionlint.yaml +++ b/.github/workflows/actionlint.yaml @@ -35,7 +35,7 @@ jobs: - name: Run actionlint with reviewdog if: steps.changed-files.outputs.workflows == 'true' - uses: reviewdog/action-actionlint@2085657ab2c7f48c58edcc767fba576f63bea76b # v1.77.0 + uses: reviewdog/action-actionlint@a8ac3eea598697a830f7d8e701fc9fcbfde88974 # v1.80.0 with: github_token: ${{ secrets.GITHUB_TOKEN }} reporter: ${{ inputs.reporter }} diff --git a/.github/workflows/claude-code-review.yaml b/.github/workflows/claude-code-review.yaml index 4d36d772..448f5f4d 100644 --- a/.github/workflows/claude-code-review.yaml +++ b/.github/workflows/claude-code-review.yaml @@ -54,7 +54,7 @@ jobs: git checkout -B "${PR_HEAD_REF}" "origin/${PR_HEAD_REF}" - name: Claude Code Review - uses: anthropics/claude-code-action@8cf3482550831fb35a4fc3fbf7ca139cf8028b4c # v1 + uses: anthropics/claude-code-action@2dca132ff0e0c4094ce6048b422c6915a071210b # v1 with: anthropic_api_key: ${{ secrets.anthropic-api-key }} # zizmor: ignore[secrets-outside-env] -- API key passed via workflow_call, not a repo secret github_token: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/claude.yaml b/.github/workflows/claude.yaml index 05e65675..70657aa6 100644 --- a/.github/workflows/claude.yaml +++ b/.github/workflows/claude.yaml @@ -27,6 +27,6 @@ jobs: - name: Run Claude Code id: claude - uses: anthropics/claude-code-action@8cf3482550831fb35a4fc3fbf7ca139cf8028b4c # v1 + uses: anthropics/claude-code-action@2dca132ff0e0c4094ce6048b422c6915a071210b # v1 with: anthropic_api_key: ${{ secrets.anthropic-api-key }} # zizmor: ignore[secrets-outside-env] -- API key passed via workflow_call, not a repo secret diff --git a/.github/workflows/claude.yml b/.github/workflows/claude.yml index dd066809..dbe91302 100644 --- a/.github/workflows/claude.yml +++ b/.github/workflows/claude.yml @@ -33,7 +33,7 @@ jobs: - name: Run Claude Code id: claude - uses: anthropics/claude-code-action@8cf3482550831fb35a4fc3fbf7ca139cf8028b4c # v1 + uses: anthropics/claude-code-action@2dca132ff0e0c4094ce6048b422c6915a071210b # v1 with: claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} # zizmor: ignore[secrets-outside-env] -- OAuth token for Claude, no dedicated environment needed