Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/actions/docs-toolchain/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,6 @@ runs:
steps:
# taiki-e/install-action fetches each tool's upstream release binary and
# verifies its checksum, so no `cargo install` compile is needed.
- uses: taiki-e/install-action@4cef1412cce204788f482e778a0b9187f9626a29 # v2.87.21
- uses: taiki-e/install-action@e407f7bafb71fd004bc5c2da3032e5470cbb6ef0 # v2.87.24
with:
tool: mdbook@${{ inputs.mdbook-version }},mdbook-toc@${{ inputs.mdbook-toc-version }},mdbook-mermaid@${{ inputs.mdbook-mermaid-version }}
14 changes: 7 additions & 7 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: taiki-e/install-action@4cef1412cce204788f482e778a0b9187f9626a29 # v2.87.21
- uses: taiki-e/install-action@e407f7bafb71fd004bc5c2da3032e5470cbb6ef0 # v2.87.24
with:
tool: zizmor@1.30.1
- name: Audit .github/workflows
Expand Down Expand Up @@ -128,7 +128,7 @@ jobs:
# The upstream RELEASE binary, pinned by version — not the runner's distro
# package, which moves under us at every runner-image refresh. Fetched by
# the same SHA-pinned installer, which verifies the checksum.
- uses: taiki-e/install-action@4cef1412cce204788f482e778a0b9187f9626a29 # v2.87.21
- uses: taiki-e/install-action@e407f7bafb71fd004bc5c2da3032e5470cbb6ef0 # v2.87.24
with:
tool: shellcheck@0.11.0
- name: Every tracked shell program is clean at severity=style
Expand Down Expand Up @@ -351,7 +351,7 @@ jobs:
with:
persist-credentials: false
- uses: ./.github/actions/setup-rust
- uses: taiki-e/install-action@4cef1412cce204788f482e778a0b9187f9626a29 # v2.87.21
- uses: taiki-e/install-action@e407f7bafb71fd004bc5c2da3032e5470cbb6ef0 # v2.87.24
with:
tool: cargo-nextest
- run: cargo nextest run --workspace --locked --no-tests=pass
Expand Down Expand Up @@ -390,7 +390,7 @@ jobs:
with:
persist-credentials: false
- uses: ./.github/actions/setup-rust
- uses: taiki-e/install-action@4cef1412cce204788f482e778a0b9187f9626a29 # v2.87.21
- uses: taiki-e/install-action@e407f7bafb71fd004bc5c2da3032e5470cbb6ef0 # v2.87.24
with:
tool: cargo-deny
# Reads the same RustSec advisory DB as cargo-audit and adds
Expand Down Expand Up @@ -503,7 +503,7 @@ jobs:
cache-key: viewer
- name: Add the WebAssembly target
run: rustup target add wasm32-unknown-unknown
- uses: taiki-e/install-action@4cef1412cce204788f482e778a0b9187f9626a29 # v2.87.21
- uses: taiki-e/install-action@e407f7bafb71fd004bc5c2da3032e5470cbb6ef0 # v2.87.24
with:
tool: trunk@0.21.14, cargo-nextest
# leptosfmt is not in install-action's manifest, so install-action would
Expand Down Expand Up @@ -589,7 +589,7 @@ jobs:
# are linked against musl, as release-build.yml links the ones it ships.
- name: Install musl tooling
run: sudo apt-get update && sudo apt-get install -y musl-tools
- uses: taiki-e/install-action@4cef1412cce204788f482e778a0b9187f9626a29 # v2.87.21
- uses: taiki-e/install-action@e407f7bafb71fd004bc5c2da3032e5470cbb6ef0 # v2.87.24
with:
tool: trunk@0.21.14, cargo-nextest
- name: The journeys hold the same formatting and lint bar
Expand Down Expand Up @@ -764,7 +764,7 @@ jobs:
with:
persist-credentials: false
- uses: ./.github/actions/setup-rust
- uses: taiki-e/install-action@4cef1412cce204788f482e778a0b9187f9626a29 # v2.87.21
- uses: taiki-e/install-action@e407f7bafb71fd004bc5c2da3032e5470cbb6ef0 # v2.87.24
with:
tool: cargo-hack
# The Cargo book's named tool for verifying the declared rust-version
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/fuzz.yml
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,7 @@ jobs:
with:
toolchain: nightly
cache-key: fuzz
- uses: taiki-e/install-action@4cef1412cce204788f482e778a0b9187f9626a29 # v2.87.21
- uses: taiki-e/install-action@e407f7bafb71fd004bc5c2da3032e5470cbb6ef0 # v2.87.24
with:
tool: cargo-fuzz@0.13.2
- name: Run the target over its seeds
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/release-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -95,7 +95,7 @@ jobs:
# architecture costs a few minutes and adds no attestation subject: the
# bundle rides inside the binary the existing lane already signs.
- name: Install Trunk
uses: taiki-e/install-action@4cef1412cce204788f482e778a0b9187f9626a29 # v2.87.21
uses: taiki-e/install-action@e407f7bafb71fd004bc5c2da3032e5470cbb6ef0 # v2.87.24
with:
tool: trunk@0.21.14
- name: Add the WebAssembly target
Expand All @@ -115,7 +115,7 @@ jobs:
# syft/trivy/grype/osv-scanner even when the release page's SBOM never
# travelled with it (https://github.com/rust-secure-code/cargo-auditable).
- name: Install cargo-auditable
uses: taiki-e/install-action@4cef1412cce204788f482e778a0b9187f9626a29 # v2.87.21
uses: taiki-e/install-action@e407f7bafb71fd004bc5c2da3032e5470cbb6ef0 # v2.87.24
with:
tool: cargo-auditable@0.7.5

Expand Down Expand Up @@ -168,7 +168,7 @@ jobs:
# actionable. Generated from the release commit's own Cargo.lock with
# `--locked`, so it describes the graph that was actually built.
- name: Install cargo-cyclonedx
uses: taiki-e/install-action@4cef1412cce204788f482e778a0b9187f9626a29 # v2.87.21
uses: taiki-e/install-action@e407f7bafb71fd004bc5c2da3032e5470cbb6ef0 # v2.87.24
with:
tool: cargo-cyclonedx
- name: Generate the dependency SBOM
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/release-image.yml
Original file line number Diff line number Diff line change
Expand Up @@ -182,7 +182,7 @@ jobs:
# syft reads the dependency list cargo-auditable embedded in the binary,
# so the SBOM names the crates, not only the two files in the image.
- name: Install syft
uses: anchore/sbom-action/download-syft@3ad7283483fc7af8ff2b4ea19663c2d5ca935e26 # v0.24.2
uses: anchore/sbom-action/download-syft@66cbf4bc1f1c0d2edc94016e65bc221b6bb0ad6c # v0.24.3
- name: Generate one SBOM per platform
env:
TAG: ${{ inputs.tag }}
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/sonar.yml
Original file line number Diff line number Diff line change
Expand Up @@ -104,7 +104,7 @@ jobs:
cache-save-if: ${{ github.ref == 'refs/heads/main' }}
- name: Install cargo-llvm-cov + cargo-nextest
if: ${{ hashFiles('Cargo.toml') != '' }}
uses: taiki-e/install-action@4cef1412cce204788f482e778a0b9187f9626a29 # v2.87.21
uses: taiki-e/install-action@e407f7bafb71fd004bc5c2da3032e5470cbb6ef0 # v2.87.24
with:
tool: cargo-llvm-cov,cargo-nextest
- name: Instrumented tests → lcov
Expand All @@ -123,7 +123,7 @@ jobs:
v="$(grep -m1 '^version = ' Cargo.toml | cut -d'"' -f2)"
echo "sonar.projectVersion=$v" >> sonar-project.properties

- uses: SonarSource/sonarqube-scan-action@ba9859eae8dd6bd29e412f25ddbbef3d032000f4 # v8.2.2
- uses: SonarSource/sonarqube-scan-action@d209202bc7d53ff1cc128f7f907dac145c9d6ae9 # v8.3.0
env:
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}

Expand Down
Loading