diff --git a/.github/workflows/pages.yml b/.github/workflows/pages.yml index 1f68580..2574a2f 100644 --- a/.github/workflows/pages.yml +++ b/.github/workflows/pages.yml @@ -9,6 +9,10 @@ # What this job does check is that the committed site is coherent — that the # demo is present and that no page links to a file that is not there. A broken # link is the one kind of rot a static site accumulates silently. +# +# Actions are pinned by commit SHA, like every other workflow here. A tag is a +# label its owner can move; a SHA is the code that was reviewed. Dependabot is +# what keeps the pins from rotting — see .github/dependabot.yml. name: Pages on: @@ -34,7 +38,7 @@ jobs: check: runs-on: ubuntu-24.04 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: The demo must be built run: | @@ -53,10 +57,10 @@ jobs: name: github-pages url: ${{ steps.deployment.outputs.page_url }} steps: - - uses: actions/checkout@v4 - - uses: actions/configure-pages@v5 - - uses: actions/upload-pages-artifact@v3 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6.0.0 + - uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0 with: path: docs - id: deployment - uses: actions/deploy-pages@v4 + uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 # v5.0.1