From 3aa3416ce5e685fc80b8c8a63cb1bcd9ca304652 Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Wed, 10 Dec 2025 20:11:56 +0000 Subject: [PATCH] Pin dependencies --- .github/workflows/ci.yml | 18 +++++++++--------- .github/workflows/close-inactive-issues.yml | 2 +- .../compose.yaml | 2 +- 3 files changed, 11 insertions(+), 11 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 7a87e76..a13b6c5 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -16,10 +16,10 @@ jobs: timeout-minutes: 30 steps: - - uses: actions/checkout@v5 + - uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5 - name: Set up JDK 17 - uses: actions/setup-java@v5 + uses: actions/setup-java@f2beeb24e141e01a676f977032f5a29d81c9e27e # v5 with: distribution: liberica java-version: 17 @@ -33,7 +33,7 @@ jobs: - name: Upload reports if: failure() - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 with: name: reports path: ./**/target/surefire-reports @@ -54,10 +54,10 @@ jobs: spring-boot-version: [ 4.0.0 ] steps: - - uses: actions/checkout@v5 + - uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5 - name: Set up JDK ${{ matrix.java }} - uses: actions/setup-java@v5 + uses: actions/setup-java@f2beeb24e141e01a676f977032f5a29d81c9e27e # v5 with: distribution: liberica java-version: ${{ matrix.java }} @@ -71,7 +71,7 @@ jobs: - name: Upload reports if: failure() - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 with: name: reports path: ./**/target/surefire-reports @@ -82,10 +82,10 @@ jobs: needs: [ test-matrix ] steps: - - uses: actions/checkout@v5 + - uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5 - name: Set up JDK 17 - uses: actions/setup-java@v5 + uses: actions/setup-java@f2beeb24e141e01a676f977032f5a29d81c9e27e # v5 with: distribution: liberica java-version: 17 @@ -108,7 +108,7 @@ jobs: - name: Upload reports if: failure() - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 with: name: reports path: ./**/target/surefire-reports diff --git a/.github/workflows/close-inactive-issues.yml b/.github/workflows/close-inactive-issues.yml index 3b37152..70e82be 100644 --- a/.github/workflows/close-inactive-issues.yml +++ b/.github/workflows/close-inactive-issues.yml @@ -7,7 +7,7 @@ jobs: close-issues: runs-on: ubuntu-latest steps: - - uses: actions/stale@v10 + - uses: actions/stale@997185467fa4f803885201cee163a9f38240193d # v10 with: days-before-issue-stale: 60 days-before-issue-close: 30 diff --git a/doma-spring-boot-samples/doma-spring-boot-sample-docker-compose/compose.yaml b/doma-spring-boot-samples/doma-spring-boot-sample-docker-compose/compose.yaml index 7c8044f..2aea1f0 100644 --- a/doma-spring-boot-samples/doma-spring-boot-sample-docker-compose/compose.yaml +++ b/doma-spring-boot-samples/doma-spring-boot-sample-docker-compose/compose.yaml @@ -1,6 +1,6 @@ services: postgres: - image: 'postgres:latest' + image: 'postgres:latest@sha256:38d5c9d522037d8bf0864c9068e4df2f8a60127c6489ab06f98fdeda535560f9' environment: - 'POSTGRES_DB=mydatabase' - 'POSTGRES_PASSWORD=secret'