diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 92b9888..aab8934 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -248,7 +248,7 @@ jobs: statuses: write steps: - name: Check the pull-request contract - uses: melodic-software/ci-workflows/.github/actions/pr-contract@5776760254f8b63cba44e896f51604cb755350d9 # v0.22.2 + uses: melodic-software/ci-workflows/.github/actions/pr-contract@541ee4e90d12d77a90a3ddd72a3af9bc78634ea7 # v0.23.0 with: token: ${{ github.token }} - name: Aggregate lane results @@ -256,7 +256,7 @@ jobs: # aggregation: the job still fails on the contract step's exit code, and # the `ci-lanes` status is on the SHA for the next contract-only run. if: ${{ !cancelled() }} - uses: melodic-software/ci-workflows/.github/actions/ci-status@5776760254f8b63cba44e896f51604cb755350d9 # v0.22.2 + uses: melodic-software/ci-workflows/.github/actions/ci-status@541ee4e90d12d77a90a3ddd72a3af9bc78634ea7 # v0.23.0 with: results: ${{ join(needs.*.result, ' ') }} # The replaced inline aggregator passed only `success`, so a `skipped` diff --git a/.github/workflows/managed-files-guard.yml b/.github/workflows/managed-files-guard.yml index 589e6b3..50f50df 100644 --- a/.github/workflows/managed-files-guard.yml +++ b/.github/workflows/managed-files-guard.yml @@ -57,7 +57,7 @@ jobs: # now contains that commit, so the pin-comment takes the convention's # release-tag form rather than the short-SHA fallback # (components/managed-files-guard/README.md). - uses: melodic-software/ci-workflows/.github/actions/managed-files-guard@5776760254f8b63cba44e896f51604cb755350d9 # v0.22.2 + uses: melodic-software/ci-workflows/.github/actions/managed-files-guard@541ee4e90d12d77a90a3ddd72a3af9bc78634ea7 # v0.23.0 with: # `main` for the soak, per the action's own input contract ("Pin to # a full SHA in callers once soak completes"): the guard must read