From 047531f71dd82eb2c9ed77e88fa542785cfb204a Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 26 Nov 2024 09:14:26 +0000 Subject: [PATCH 1/2] Bump actions/checkout in /.github/workflows in the actions group Bumps the actions group in /.github/workflows with 1 update: [actions/checkout](https://github.com/actions/checkout). Updates `actions/checkout` from 2 to 4 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/v2...v4) --- updated-dependencies: - dependency-name: actions/checkout dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions ... Signed-off-by: dependabot[bot] --- .github/workflows/test_action.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/test_action.yml b/.github/workflows/test_action.yml index f7ca0a9..66c11ff 100644 --- a/.github/workflows/test_action.yml +++ b/.github/workflows/test_action.yml @@ -9,7 +9,7 @@ jobs: name: Test action runs-on: ubuntu-20.04 steps: - - uses: actions/checkout@v2 + - uses: actions/checkout@v4 - id: build uses: OpenAstronomy/build-python-dist@v1 with: @@ -25,7 +25,7 @@ jobs: name: Test action (no keep option specified) runs-on: ubuntu-20.04 steps: - - uses: actions/checkout@v2 + - uses: actions/checkout@v4 - id: build uses: OpenAstronomy/build-python-dist@v1 with: From ef674fa8107f9f4c8c9e4ed04a9b0780a8a20acc Mon Sep 17 00:00:00 2001 From: Stuart Mumford Date: Tue, 26 Nov 2024 09:16:21 +0000 Subject: [PATCH 2/2] Use hashes --- .github/workflows/test_action.yml | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/test_action.yml b/.github/workflows/test_action.yml index 66c11ff..ac7ffc4 100644 --- a/.github/workflows/test_action.yml +++ b/.github/workflows/test_action.yml @@ -9,9 +9,9 @@ jobs: name: Test action runs-on: ubuntu-20.04 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - id: build - uses: OpenAstronomy/build-python-dist@v1 + uses: OpenAstronomy/build-python-dist@bbb0e1c5b132893999ea56d77bd4b526e0097c7d # v1.0.1 with: pure_python_wheel: true - id: upload @@ -25,9 +25,9 @@ jobs: name: Test action (no keep option specified) runs-on: ubuntu-20.04 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - id: build - uses: OpenAstronomy/build-python-dist@v1 + uses: OpenAstronomy/build-python-dist@bbb0e1c5b132893999ea56d77bd4b526e0097c7d # v1.0.1 with: pure_python_wheel: true - id: upload