diff --git a/.github/workflows/build-lint-test.yml b/.github/workflows/build-lint-test.yml index 0a1fabb507..34c46a5088 100644 --- a/.github/workflows/build-lint-test.yml +++ b/.github/workflows/build-lint-test.yml @@ -20,7 +20,7 @@ jobs: node-version: [20.x, 22.x] steps: - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: false node-version: ${{ matrix.node-version }} @@ -30,7 +30,7 @@ jobs: run: yarn workspace @metamask/snaps-execution-environments run build:lavamoat:test - name: Save "@metamask/snaps-execution-environments" build id: cache-snaps-execution-environments-build - uses: actions/upload-artifact@v7 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: snaps-execution-environments-build-${{ runner.os }}-${{ matrix.node-version }}-${{ github.sha }} retention-days: 1 @@ -54,13 +54,13 @@ jobs: needs: prepare steps: - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: false - name: Build run: yarn build:ci - name: Save build files - uses: actions/upload-artifact@v7 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: build-source-${{ runner.os }}-${{ github.sha }} retention-days: 1 @@ -82,7 +82,7 @@ jobs: needs: prepare steps: - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: false - name: Build @@ -101,7 +101,7 @@ jobs: needs: prepare steps: - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: false - name: Build JSON-RPC schema @@ -113,11 +113,11 @@ jobs: needs: build steps: - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: false - name: Restore build files - uses: actions/download-artifact@v8 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: build-source-${{ runner.os }}-${{ github.sha }} - name: Generate LavaMoat policy @@ -136,7 +136,7 @@ jobs: needs: prepare steps: - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: false - name: Lint @@ -164,30 +164,30 @@ jobs: package-name: ${{ fromJson(needs.prepare.outputs.test-workspace-package-names) }} steps: - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: false node-version: ${{ matrix.node-version }} - name: Restore "@metamask/snaps-execution-environments" build - uses: actions/download-artifact@v8 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: snaps-execution-environments-build-${{ runner.os }}-${{ matrix.node-version }}-${{ github.sha }} - name: Restore build files - uses: actions/download-artifact@v8 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: build-source-${{ runner.os }}-${{ github.sha }} - name: Install browsers if: ${{ matrix.package-name == '@metamask/snaps-controllers' || matrix.package-name == '@metamask/snaps-execution-environments' || matrix.package-name == '@metamask/snaps-utils' }} - uses: MetaMask/action-retry-command@v1 + uses: MetaMask/action-retry-command@2377689bfd9a03010a956b7c14273a2fc43d20cf # v1.0.1 with: command: yarn playwright install --with-deps --only-shell chromium firefox - name: Run tests - uses: MetaMask/action-retry-command@v1 + uses: MetaMask/action-retry-command@2377689bfd9a03010a956b7c14273a2fc43d20cf # v1.0.1 with: command: yarn workspace ${{ matrix.package-name }} run test - name: Run Firefox tests if: ${{ matrix.package-name == '@metamask/snaps-controllers' || matrix.package-name == '@metamask/snaps-execution-environments' || matrix.package-name == '@metamask/snaps-utils' }} - uses: MetaMask/action-retry-command@v1 + uses: MetaMask/action-retry-command@2377689bfd9a03010a956b7c14273a2fc43d20cf # v1.0.1 with: command: yarn workspace ${{ matrix.package-name }} run test:browser:firefox - name: Get coverage folder @@ -198,7 +198,7 @@ jobs: shell: bash - name: Upload coverage artifact if: ${{ matrix.node-version == '22.x' }} - uses: actions/upload-artifact@v7 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: coverage-${{ steps.get-coverage-folder.outputs.artifact-name }} path: | @@ -219,9 +219,9 @@ jobs: runs-on: ubuntu-latest needs: test steps: - - uses: actions/checkout@v7 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Download coverage artifact - uses: actions/download-artifact@v8 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: pattern: coverage-* merge-multiple: true @@ -244,22 +244,22 @@ jobs: package-name: ${{ fromJson(needs.prepare.outputs.e2e-workspace-package-names) }} steps: - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: false node-version: ${{ matrix.node-version }} - name: Restore "@metamask/snaps-execution-environments" build - uses: actions/download-artifact@v8 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: snaps-execution-environments-build-${{ runner.os }}-${{ matrix.node-version }}-${{ github.sha }} - name: Restore build files - uses: actions/download-artifact@v8 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: build-source-${{ runner.os }}-${{ github.sha }} - name: Build snap run: yarn workspace ${{ matrix.package-name }} run build - name: Run E2E tests - uses: MetaMask/action-retry-command@v1 + uses: MetaMask/action-retry-command@2377689bfd9a03010a956b7c14273a2fc43d20cf # v1.0.1 with: command: yarn workspace ${{ matrix.package-name }} run test - name: Require clean working directory @@ -279,12 +279,12 @@ jobs: os: [macOS-latest, windows-latest] steps: - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: false - name: Build dependencies run: yarn build:ci - name: Run tests - uses: MetaMask/action-retry-command@v1 + uses: MetaMask/action-retry-command@2377689bfd9a03010a956b7c14273a2fc43d20cf # v1.0.1 with: command: yarn workspace @metamask/snaps-cli run test diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml index 500ca6202b..c3995af62a 100644 --- a/.github/workflows/main.yml +++ b/.github/workflows/main.yml @@ -19,13 +19,13 @@ jobs: skip-merge-queue: ${{ steps.check-skip-merge-queue.outputs.up-to-date }} steps: - name: Checkout repository - uses: actions/checkout@v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 if: github.event_name == 'merge_group' - name: Check pull request merge queue status id: check-skip-merge-queue if: github.event_name == 'merge_group' - uses: MetaMask/github-tools/.github/actions/check-skip-merge-queue@v1 + uses: MetaMask/github-tools/.github/actions/check-skip-merge-queue@7e0d74bc7b79ce9601e52f58d5e4d36c19591df9 # v1.19.0 check-workflows: name: Check workflows @@ -34,7 +34,7 @@ jobs: if: github.event_name != 'merge_group' || needs.check-skip-merge-queue.outputs.skip-merge-queue != 'true' steps: - name: Checkout repository - uses: actions/checkout@v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Download actionlint id: download-actionlint run: bash <(curl https://raw.githubusercontent.com/rhysd/actionlint/7fdc9630cc360ea1a469eed64ac6d78caeda1234/scripts/download-actionlint.bash) 1.7.7 @@ -46,7 +46,7 @@ jobs: analyse-code: name: Analyse code needs: check-workflows - uses: MetaMask/action-security-code-scanner/.github/workflows/security-scan.yml@v2 + uses: MetaMask/action-security-code-scanner/.github/workflows/security-scan.yml@becb242930b3cc271c26da0280050db9c157e291 # v2.1.1 with: scanner-ref: v2 paths-ignored: | @@ -109,7 +109,7 @@ jobs: IS_RELEASE: ${{ steps.is-release.outputs.IS_RELEASE }} steps: - id: is-release - uses: MetaMask/action-is-release@v2 + uses: MetaMask/action-is-release@3cd51b98fa98d1347d06f5961299b0172ee31ae8 # v2.3.0 with: commit-starts-with: 'Release [version],Release `[version]`,release: [version],release: `[version]`' diff --git a/.github/workflows/publish-environment.yml b/.github/workflows/publish-environment.yml index 2504e5e0f8..c8ca6f249f 100644 --- a/.github/workflows/publish-environment.yml +++ b/.github/workflows/publish-environment.yml @@ -20,7 +20,7 @@ jobs: if: ${{ inputs.destination_dir == '' }} run: exit 1 - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: true - name: Build dependencies diff --git a/.github/workflows/publish-github-pages.yml b/.github/workflows/publish-github-pages.yml index d25e799afd..5a939f5da6 100644 --- a/.github/workflows/publish-github-pages.yml +++ b/.github/workflows/publish-github-pages.yml @@ -33,13 +33,13 @@ jobs: run: exit 1 - name: Get access token id: get-token - uses: MetaMask/github-tools/.github/actions/get-token@v1 + uses: MetaMask/github-tools/.github/actions/get-token@7e0d74bc7b79ce9601e52f58d5e4d36c19591df9 # v1.19.0 with: token-exchange-url: ${{ vars.TOKEN_EXCHANGE_URL }} permissions: | contents: write - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: true - name: Run build script diff --git a/.github/workflows/publish-preview.yml b/.github/workflows/publish-preview.yml index dc445112f5..2d610f9f2f 100644 --- a/.github/workflows/publish-preview.yml +++ b/.github/workflows/publish-preview.yml @@ -12,7 +12,7 @@ jobs: outputs: IS_FORK: ${{ steps.is-fork.outputs.IS_FORK }} steps: - - uses: actions/checkout@v7 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Determine whether this PR is from a fork id: is-fork run: echo "IS_FORK=$(gh pr view --json isCrossRepository --jq '.isCrossRepository' "${PR_NUMBER}" )" >> "$GITHUB_OUTPUT" @@ -29,14 +29,14 @@ jobs: if: ${{ needs.is-fork-pull-request.outputs.IS_FORK == 'false' }} runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Checkout pull request run: gh pr checkout "${PR_NUMBER}" env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} PR_NUMBER: ${{ github.event.issue.number }} - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: true - name: Get commit SHA diff --git a/.github/workflows/publish-release.yml b/.github/workflows/publish-release.yml index 947bdf7766..85eb65cfce 100644 --- a/.github/workflows/publish-release.yml +++ b/.github/workflows/publish-release.yml @@ -35,7 +35,7 @@ jobs: tag: ${{ steps.get-release-tag.outputs.tag }} steps: - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: true ref: ${{ github.sha }} @@ -52,12 +52,12 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: true ref: ${{ github.sha }} - name: Publish release to GitHub - uses: MetaMask/action-publish-release@v3 + uses: MetaMask/action-publish-release@f01f1be110d60fb07d86c880ce3d6bdb353524d3 # v3.3.1 id: publish-release with: npm-tag: ${{ needs.get-release-tag.outputs.tag }} @@ -70,7 +70,7 @@ jobs: - name: Build test-snaps run: yarn workspace @metamask/test-snaps build - name: Upload build artifacts - uses: actions/upload-artifact@v7 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: publish-release-artifacts-${{ github.sha }} include-hidden-files: true @@ -86,16 +86,16 @@ jobs: needs: publish-release steps: - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: true ref: ${{ github.sha }} - name: Restore build artifacts - uses: actions/download-artifact@v8 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: publish-release-artifacts-${{ github.sha }} - name: Dry run publish to NPM - uses: MetaMask/action-npm-publish@v6 + uses: MetaMask/action-npm-publish@18df42148c35aabb98e00f9fda127d421af141df # v6.5.0 with: slack-webhook-url: ${{ secrets.SLACK_WEBHOOK_URL }} subteam: ${{ inputs.slack-subteam }} @@ -113,16 +113,16 @@ jobs: id-token: write steps: - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: true ref: ${{ github.sha }} - name: Restore build artifacts - uses: actions/download-artifact@v8 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: publish-release-artifacts-${{ github.sha }} - name: Publish ${{ needs.get-release-tag.outputs.tag }} to NPM - uses: MetaMask/action-npm-publish@v6 + uses: MetaMask/action-npm-publish@18df42148c35aabb98e00f9fda127d421af141df # v6.5.0 with: npm-token: ${{ secrets.NPM_TOKEN }} npm-tag: ${{ needs.get-release-tag.outputs.tag }} @@ -148,7 +148,7 @@ jobs: SDK_VERSION: ${{ steps.set-output.outputs.SDK_VERSION }} steps: - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: true ref: ${{ github.sha }} @@ -199,7 +199,7 @@ jobs: IS_ENVIRONMENT_RELEASE: ${{ steps.is-environment-release.outputs.IS_ENVIRONMENT_RELEASE }} steps: - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: true ref: ${{ github.sha }} @@ -221,7 +221,7 @@ jobs: version: ${{ steps.version.outputs.VERSION }} steps: - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: true ref: ${{ github.sha }} @@ -288,7 +288,7 @@ jobs: TEST_SNAPS_VERSION: ${{ steps.set-output.outputs.TEST_SNAPS_VERSION }} steps: - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: true ref: ${{ github.sha }} diff --git a/.github/workflows/update-pull-request.yml b/.github/workflows/update-pull-request.yml index 38accc00dd..b6d7285598 100644 --- a/.github/workflows/update-pull-request.yml +++ b/.github/workflows/update-pull-request.yml @@ -34,7 +34,7 @@ jobs: pull-requests: read steps: - name: Checkout repository - uses: actions/checkout@v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Determine whether this PR is from a fork id: is-fork run: echo "IS_FORK=$(gh pr view --json isCrossRepository --jq '.isCrossRepository' "${PR_NUMBER}" )" >> "$GITHUB_OUTPUT" @@ -55,7 +55,7 @@ jobs: steps: - name: Get access token id: get-token - uses: MetaMask/github-tools/.github/actions/get-token@v1 + uses: MetaMask/github-tools/.github/actions/get-token@7e0d74bc7b79ce9601e52f58d5e4d36c19591df9 # v1.19.0 with: token-exchange-url: ${{ vars.TOKEN_EXCHANGE_URL }} permissions: | @@ -90,7 +90,7 @@ jobs: steps: - name: Get access token id: get-token - uses: MetaMask/github-tools/.github/actions/get-token@v1 + uses: MetaMask/github-tools/.github/actions/get-token@7e0d74bc7b79ce9601e52f58d5e4d36c19591df9 # v1.19.0 with: token-exchange-url: ${{ vars.TOKEN_EXCHANGE_URL }} permissions: | @@ -98,7 +98,7 @@ jobs: pull_requests: read - name: Checkout repository - uses: actions/checkout@v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Checkout pull request run: gh pr checkout "${PR_NUMBER}" @@ -107,7 +107,7 @@ jobs: PR_NUMBER: ${{ inputs.pull-request != 0 && inputs.pull-request || github.event.issue.number }} - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: false cache-node-modules: true @@ -129,7 +129,7 @@ jobs: steps: - name: Get access token id: get-token - uses: MetaMask/github-tools/.github/actions/get-token@v1 + uses: MetaMask/github-tools/.github/actions/get-token@7e0d74bc7b79ce9601e52f58d5e4d36c19591df9 # v1.19.0 with: token-exchange-url: ${{ vars.TOKEN_EXCHANGE_URL }} permissions: | @@ -137,7 +137,7 @@ jobs: pull_requests: read - name: Checkout repository - uses: actions/checkout@v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Checkout pull request run: gh pr checkout "${PR_NUMBER}" @@ -146,7 +146,7 @@ jobs: PR_NUMBER: ${{ inputs.pull-request != 0 && inputs.pull-request || github.event.issue.number }} - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: is-high-risk-environment: false @@ -159,7 +159,7 @@ jobs: git diff --exit-code yarn.lock || echo "YARN_LOCK_CHANGED=true" >> "$GITHUB_OUTPUT" - name: Save yarn.lock - uses: actions/upload-artifact@v7 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: yarn-lock-${{ needs.prepare.outputs.COMMIT_SHA }} path: yarn.lock @@ -177,7 +177,7 @@ jobs: steps: - name: Get access token id: get-token - uses: MetaMask/github-tools/.github/actions/get-token@v1 + uses: MetaMask/github-tools/.github/actions/get-token@7e0d74bc7b79ce9601e52f58d5e4d36c19591df9 # v1.19.0 with: token-exchange-url: ${{ vars.TOKEN_EXCHANGE_URL }} permissions: | @@ -185,7 +185,7 @@ jobs: pull_requests: read - name: Checkout repository - uses: actions/checkout@v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Checkout pull request run: gh pr checkout "${PR_NUMBER}" @@ -194,18 +194,18 @@ jobs: PR_NUMBER: ${{ inputs.pull-request != 0 && inputs.pull-request || github.event.issue.number }} - name: Restore yarn.lock - uses: actions/download-artifact@v8 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: yarn-lock-${{ needs.prepare.outputs.COMMIT_SHA }} - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: # If the Yarn lock changed we need to reinstall the dependencies. is-high-risk-environment: ${{ needs.dedupe-yarn-lock.outputs.YARN_LOCK_CHANGED == 'true' }} - name: Build packages run: yarn build:ci - name: Save packages - uses: actions/upload-artifact@v7 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: packages-${{ needs.prepare.outputs.COMMIT_SHA }} path: | @@ -226,7 +226,7 @@ jobs: steps: - name: Get access token id: get-token - uses: MetaMask/github-tools/.github/actions/get-token@v1 + uses: MetaMask/github-tools/.github/actions/get-token@7e0d74bc7b79ce9601e52f58d5e4d36c19591df9 # v1.19.0 with: token-exchange-url: ${{ vars.TOKEN_EXCHANGE_URL }} permissions: | @@ -234,7 +234,7 @@ jobs: pull_requests: read - name: Checkout repository - uses: actions/checkout@v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Checkout pull request run: gh pr checkout "${PR_NUMBER}" @@ -243,17 +243,17 @@ jobs: PR_NUMBER: ${{ inputs.pull-request != 0 && inputs.pull-request || github.event.issue.number }} - name: Restore yarn.lock - uses: actions/download-artifact@v8 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: yarn-lock-${{ needs.prepare.outputs.COMMIT_SHA }} - name: Restore packages - uses: actions/download-artifact@v8 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: packages-${{ needs.prepare.outputs.COMMIT_SHA }} - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: # If the Yarn lock changed we need to reinstall the dependencies. is-high-risk-environment: ${{ needs.dedupe-yarn-lock.outputs.YARN_LOCK_CHANGED == 'true' }} @@ -262,7 +262,7 @@ jobs: run: yarn build:lavamoat:policy - name: Save LavaMoat policies - uses: actions/upload-artifact@v7 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: lavamoat-policies-${{ needs.prepare.outputs.COMMIT_SHA }} path: | @@ -283,7 +283,7 @@ jobs: steps: - name: Get access token id: get-token - uses: MetaMask/github-tools/.github/actions/get-token@v1 + uses: MetaMask/github-tools/.github/actions/get-token@7e0d74bc7b79ce9601e52f58d5e4d36c19591df9 # v1.19.0 with: token-exchange-url: ${{ vars.TOKEN_EXCHANGE_URL }} permissions: | @@ -291,7 +291,7 @@ jobs: pull_requests: read - name: Checkout repository - uses: actions/checkout@v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Checkout pull request run: gh pr checkout "${PR_NUMBER}" @@ -300,17 +300,17 @@ jobs: PR_NUMBER: ${{ inputs.pull-request != 0 && inputs.pull-request || github.event.issue.number }} - name: Restore yarn.lock - uses: actions/download-artifact@v8 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: yarn-lock-${{ needs.prepare.outputs.COMMIT_SHA }} - name: Restore packages - uses: actions/download-artifact@v8 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: packages-${{ needs.prepare.outputs.COMMIT_SHA }} - name: Checkout and setup environment - uses: MetaMask/action-checkout-and-setup@v3 + uses: MetaMask/action-checkout-and-setup@0543b5929698c71e3ccc6ed24eac87825669b5de # v3.5.0 with: # If the Yarn lock changed we need to reinstall the dependencies. is-high-risk-environment: ${{ needs.dedupe-yarn-lock.outputs.YARN_LOCK_CHANGED == 'true' }} @@ -319,7 +319,7 @@ jobs: run: yarn build:examples - name: Save examples - uses: actions/upload-artifact@v7 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: examples-${{ needs.prepare.outputs.COMMIT_SHA }} path: | @@ -343,7 +343,7 @@ jobs: steps: - name: Get access token id: get-token - uses: MetaMask/github-tools/.github/actions/get-token@v1 + uses: MetaMask/github-tools/.github/actions/get-token@7e0d74bc7b79ce9601e52f58d5e4d36c19591df9 # v1.19.0 with: token-exchange-url: ${{ vars.TOKEN_EXCHANGE_URL }} permissions: | @@ -351,7 +351,7 @@ jobs: pull_requests: read - name: Checkout repository - uses: actions/checkout@v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: # Use PAT to ensure that the commit later can trigger status check # workflows. @@ -373,7 +373,7 @@ jobs: run: echo "COMMIT_SHA=$(git rev-parse --short HEAD)" >> "$GITHUB_OUTPUT" - name: Restore yarn.lock - uses: actions/download-artifact@v8 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: yarn-lock-${{ needs.prepare.outputs.COMMIT_SHA }} @@ -387,7 +387,7 @@ jobs: git commit -m "${COMMIT_PREFIX}Deduplicate yarn.lock" || true - name: Restore LavaMoat policies - uses: actions/download-artifact@v8 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: lavamoat-policies-${{ needs.prepare.outputs.COMMIT_SHA }} @@ -397,7 +397,7 @@ jobs: git commit -m "${COMMIT_PREFIX}Update LavaMoat policies" || true - name: Restore examples - uses: actions/download-artifact@v8 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: examples-${{ needs.prepare.outputs.COMMIT_SHA }}