diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index cd6fb59..f532f03 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -108,7 +108,7 @@ jobs: actions: read steps: - name: Check the pull-request contract - uses: melodic-software/ci-workflows/.github/actions/pr-contract@5776760254f8b63cba44e896f51604cb755350d9 # v0.22.2 + uses: melodic-software/ci-workflows/.github/actions/pr-contract@2c1de45aa0e1b1489afb8edfebc12cb3a4fa6ac3 # v0.24.0 with: token: ${{ github.token }} - name: Aggregate lane results @@ -116,7 +116,7 @@ jobs: # aggregation: the job still fails on the contract step's exit code, and # the `ci-lanes` status is on the SHA for the next contract-only run. if: ${{ !cancelled() }} - uses: melodic-software/ci-workflows/.github/actions/ci-status@5776760254f8b63cba44e896f51604cb755350d9 # v0.22.2 + uses: melodic-software/ci-workflows/.github/actions/ci-status@2c1de45aa0e1b1489afb8edfebc12cb3a4fa6ac3 # v0.24.0 with: # At least 60 seconds below this job's `timeout-minutes: 5` (300s), so # the fail-closed error is what a contract-only run reports at the diff --git a/.github/workflows/managed-files-guard.yml b/.github/workflows/managed-files-guard.yml index 589e6b3..3fe74e4 100644 --- a/.github/workflows/managed-files-guard.yml +++ b/.github/workflows/managed-files-guard.yml @@ -57,7 +57,7 @@ jobs: # now contains that commit, so the pin-comment takes the convention's # release-tag form rather than the short-SHA fallback # (components/managed-files-guard/README.md). - uses: melodic-software/ci-workflows/.github/actions/managed-files-guard@5776760254f8b63cba44e896f51604cb755350d9 # v0.22.2 + uses: melodic-software/ci-workflows/.github/actions/managed-files-guard@2c1de45aa0e1b1489afb8edfebc12cb3a4fa6ac3 # v0.24.0 with: # `main` for the soak, per the action's own input contract ("Pin to # a full SHA in callers once soak completes"): the guard must read