diff --git a/.github/workflows/autofix.yml b/.github/workflows/autofix.yml index c9fbcc4..8b8209e 100644 --- a/.github/workflows/autofix.yml +++ b/.github/workflows/autofix.yml @@ -15,4 +15,4 @@ permissions: jobs: dependabot-bun-dedupe: - uses: stella/.github/.github/workflows/dependabot-bun-dedupe.yml@dd6e8fa51339814159486cd92b5ae3a051eb15d2 + uses: stella/.github/.github/workflows/dependabot-bun-dedupe.yml@412fb4b9cfc8c2b630acdca9cb465d312fe5e362 diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index e7d60f3..55794b0 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -143,7 +143,7 @@ jobs: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2 - run: bun install --frozen-lockfile - - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 + - uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 - name: Install pinned cross-language oracle packages run: | uv venv .venv --python python3 @@ -217,7 +217,7 @@ jobs: # snapshot-hygiene gate, `cargo ci-snapshot`); avoids a from-source # compile on every CI run. taiki-e/install-action verifies release # checksums, unlike a raw `curl | tar`. - uses: taiki-e/install-action@3f74d7c16a4242f1c95561e98edc25d36adb4375 # v2.87.12 + uses: taiki-e/install-action@94c31af3204a9f15ab40b35ad084410b905bbc73 # v2.87.17 with: tool: nextest@0.9.140,cargo-deny@0.20.2,cargo-insta@1.48.0 @@ -284,7 +284,7 @@ jobs: - run: bun run smoke:wasm - run: bun run smoke:browser - run: bun run readme:check - - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 + - uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 - name: Build the Python abi3 wheel uses: PyO3/maturin-action@e83996d129638aa358a18fbd1dfb82f0b0fb5d3b # v1.51.0 with: diff --git a/.github/workflows/cla.yml b/.github/workflows/cla.yml index 9304b1a..a7cf725 100644 --- a/.github/workflows/cla.yml +++ b/.github/workflows/cla.yml @@ -26,7 +26,7 @@ jobs: || github.event.comment.body == 'I have read the CLA Document and I hereby sign the CLA' ) ) - uses: stella/.github/.github/workflows/cla.yml@48aacae31829ce15216a6b766b03a92fd2e84da3 + uses: stella/.github/.github/workflows/cla.yml@412fb4b9cfc8c2b630acdca9cb465d312fe5e362 with: allowlist: dependabot[bot],renovate[bot],github-actions[bot],google-labs-jules[bot],cursoragent,stella-provenance-updater[bot],autofix-ci[bot] secrets: diff --git a/.github/workflows/mutants.yml b/.github/workflows/mutants.yml index d0472de..338f968 100644 --- a/.github/workflows/mutants.yml +++ b/.github/workflows/mutants.yml @@ -34,7 +34,7 @@ jobs: - name: Install pinned Rust tools (checksum-verified) # nextest is the test runner used by cargo-mutants. taiki-e/install-action # verifies release checksums, unlike a raw `curl | tar`. - uses: taiki-e/install-action@3f74d7c16a4242f1c95561e98edc25d36adb4375 # v2.87.12 + uses: taiki-e/install-action@94c31af3204a9f15ab40b35ad084410b905bbc73 # v2.87.17 with: tool: nextest@0.9.140,cargo-mutants@27.1.0 diff --git a/.github/workflows/quarantine-policy.yml b/.github/workflows/quarantine-policy.yml index bbac3ff..62efe62 100644 --- a/.github/workflows/quarantine-policy.yml +++ b/.github/workflows/quarantine-policy.yml @@ -13,4 +13,4 @@ jobs: if: github.repository == 'stella/stdnum' permissions: contents: read - uses: stella/.github/.github/workflows/quarantine-policy.yml@9e1915536efc226c5ec9d3ca0f2192be5aa6ec7e + uses: stella/.github/.github/workflows/quarantine-policy.yml@412fb4b9cfc8c2b630acdca9cb465d312fe5e362 diff --git a/.github/workflows/quarantine-prune.yml b/.github/workflows/quarantine-prune.yml index 711b70c..9472f05 100644 --- a/.github/workflows/quarantine-prune.yml +++ b/.github/workflows/quarantine-prune.yml @@ -13,7 +13,7 @@ jobs: if: github.repository == 'stella/stdnum' permissions: contents: read - uses: stella/.github/.github/workflows/quarantine-prune.yml@9e1915536efc226c5ec9d3ca0f2192be5aa6ec7e + uses: stella/.github/.github/workflows/quarantine-prune.yml@412fb4b9cfc8c2b630acdca9cb465d312fe5e362 secrets: CHANGELOG_APP_ID: ${{ secrets.CHANGELOG_APP_ID }} CHANGELOG_APP_PRIVATE_KEY: ${{ secrets.CHANGELOG_APP_PRIVATE_KEY }} diff --git a/.github/workflows/release-policy.yml b/.github/workflows/release-policy.yml index d8ced8f..bd478a7 100644 --- a/.github/workflows/release-policy.yml +++ b/.github/workflows/release-policy.yml @@ -18,6 +18,6 @@ permissions: jobs: enforce: name: Enforce release boundaries - uses: stella/.github/.github/workflows/release-policy.yml@0f814e1a0c6c7401778e661209553b6e15f8d92a + uses: stella/.github/.github/workflows/release-policy.yml@412fb4b9cfc8c2b630acdca9cb465d312fe5e362 permissions: contents: read diff --git a/.github/workflows/release-pr.yml b/.github/workflows/release-pr.yml index 14b64a4..8ff351f 100644 --- a/.github/workflows/release-pr.yml +++ b/.github/workflows/release-pr.yml @@ -15,7 +15,7 @@ jobs: name: Maintain version packages PR permissions: contents: read - uses: stella/.github/.github/workflows/changeset-release-pr.yml@c56b0c1d1e82f5e3fffa733a32b9a503a172ee35 + uses: stella/.github/.github/workflows/changeset-release-pr.yml@412fb4b9cfc8c2b630acdca9cb465d312fe5e362 with: bun-version-file: package.json sync-cargo-inherited-lock: true diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index add6aeb..b30abe4 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -331,7 +331,7 @@ jobs: id-token: write # Required only for PyPI trusted publishing. steps: - name: Prepare exact Python wheel set - uses: stella/.github/.github/actions/pypi-publish-hardened@0f814e1a0c6c7401778e661209553b6e15f8d92a + uses: stella/.github/.github/actions/pypi-publish-hardened@412fb4b9cfc8c2b630acdca9cb465d312fe5e362 with: expected-version: ${{ needs.verify.outputs.version }} project-name: stella-stdnum @@ -344,7 +344,7 @@ jobs: packages-dir: dist skip-existing: true - name: Verify published PyPI files - uses: stella/.github/.github/actions/pypi-publish-hardened/verify@0f814e1a0c6c7401778e661209553b6e15f8d92a + uses: stella/.github/.github/actions/pypi-publish-hardened/verify@412fb4b9cfc8c2b630acdca9cb465d312fe5e362 with: expected-version: ${{ needs.verify.outputs.version }} project-name: stella-stdnum @@ -354,7 +354,7 @@ jobs: needs: [verify, pack-native, pack-portable, publish-pypi] if: github.ref == 'refs/heads/main' && (needs.verify.outputs.publish == 'true') - uses: stella/.github/.github/workflows/npm-version-finalize.yml@0f814e1a0c6c7401778e661209553b6e15f8d92a + uses: stella/.github/.github/workflows/npm-version-finalize.yml@412fb4b9cfc8c2b630acdca9cb465d312fe5e362 with: package-files: | packages/stdnum/package.json diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index f2675bb..1b0f276 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -30,6 +30,6 @@ jobs: publish_results: true - name: Upload SARIF to GitHub Security tab - uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 + uses: github/codeql-action/upload-sarif@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 with: sarif_file: results.sarif