Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/ci-feedback.yml
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@ jobs:
# tree. Either way `./actions/ci-feedback` cannot resolve, which is how
# 0.1.21 shipped this path broken for every reusable caller. Name the
# repository explicitly and pin it.
- uses: NDDev-OpenNetwork/ci-workflows/actions/ci-feedback@96215b32fbc751716b5c0b758a7a7ca202246574 # 0.1.23
- uses: NDDev-OpenNetwork/ci-workflows/actions/ci-feedback@a7b90bdf1ac12465cbd07072e3360442cfc8eec6 # 0.1.26
with:
run-id: ${{ inputs.run-id }}
run-attempt: ${{ inputs.run-attempt }}
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -68,7 +68,7 @@ jobs:
python-version: "3.13"
update-environment: false
- name: Set up uv
uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
version: 0.11.30
# Stated, not inherited -- and it does change something. The pinned
Expand Down Expand Up @@ -124,7 +124,7 @@ jobs:
python-version: "3.13"
update-environment: false
- name: Set up uv
uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
version: 0.11.30
# Stated, not inherited -- and it does change something. The pinned
Expand Down Expand Up @@ -299,7 +299,7 @@ jobs:
update-environment: false

- name: Set up uv
uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
version: 0.11.30
enable-cache: false
Expand Down Expand Up @@ -396,7 +396,7 @@ jobs:
update-environment: false

- name: Set up uv
uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
version: 0.11.30
enable-cache: false
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/dependabot-catalog-convergence.yml
Original file line number Diff line number Diff line change
Expand Up @@ -86,7 +86,7 @@ jobs:
python-version: "3.13"
update-environment: false
- name: Set up uv
uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
version: 0.11.30
enable-cache: false
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/maintenance.yml
Original file line number Diff line number Diff line change
Expand Up @@ -82,7 +82,7 @@ jobs:
update-environment: false

- name: Set up uv
uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
version: 0.11.30
# The sweep decides what maintenance debt exists; it must not
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/nddev-security-bundle.yml
Original file line number Diff line number Diff line change
Expand Up @@ -116,7 +116,7 @@ jobs:
"$source_root/scripts/run_private_security_bundle.sh" >> "$GITHUB_ENV"

- name: Set up pinned uv
uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
version: 0.11.30
enable-cache: false
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/private-security-bundle-free.yml
Original file line number Diff line number Diff line change
Expand Up @@ -150,7 +150,7 @@ jobs:
- name: Restore pinned uv archive
if: ${{ steps.baked-uv.outputs.available != 'true' }}
id: uv-archive
uses: NDDev-OpenNetwork/ci-workflows/actions/tool-cache@96215b32fbc751716b5c0b758a7a7ca202246574 # 0.1.23
uses: NDDev-OpenNetwork/ci-workflows/actions/tool-cache@a7b90bdf1ac12465cbd07072e3360442cfc8eec6 # 0.1.26
with:
url: https://github.com/astral-sh/uv/releases/download/0.11.30/uv-x86_64-unknown-linux-gnu.tar.gz
sha256: 04bc7d180d6138bf6dc08387acf507a823f397a98fea55da36b0ccc7fbce3b68
Expand All @@ -173,23 +173,23 @@ jobs:
printf '%s\n' "$RUNNER_TEMP/private-security-tools/bin" >> "$GITHUB_PATH"

- name: Restore actionlint archive
uses: NDDev-OpenNetwork/ci-workflows/actions/tool-cache@96215b32fbc751716b5c0b758a7a7ca202246574 # 0.1.23
uses: NDDev-OpenNetwork/ci-workflows/actions/tool-cache@a7b90bdf1ac12465cbd07072e3360442cfc8eec6 # 0.1.26
with:
url: https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_linux_amd64.tar.gz
sha256: 8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8
output: ${{ runner.temp }}/private-security-tools/actionlint.tar.gz
max-bytes: '16777216'

- name: Restore OSV-Scanner binary
uses: NDDev-OpenNetwork/ci-workflows/actions/tool-cache@96215b32fbc751716b5c0b758a7a7ca202246574 # 0.1.23
uses: NDDev-OpenNetwork/ci-workflows/actions/tool-cache@a7b90bdf1ac12465cbd07072e3360442cfc8eec6 # 0.1.26
with:
url: https://github.com/google/osv-scanner/releases/download/v2.6.0/osv-scanner_linux_amd64
sha256: ca69b3d3cd08f889a49dc0a383122f71cc528b83803671df5fd874d97485b108
output: ${{ runner.temp }}/private-security-tools/osv-scanner
max-bytes: '268435456'

- name: Restore gitleaks archive
uses: NDDev-OpenNetwork/ci-workflows/actions/tool-cache@96215b32fbc751716b5c0b758a7a7ca202246574 # 0.1.23
uses: NDDev-OpenNetwork/ci-workflows/actions/tool-cache@a7b90bdf1ac12465cbd07072e3360442cfc8eec6 # 0.1.26
with:
url: https://github.com/gitleaks/gitleaks/releases/download/v8.30.1/gitleaks_8.30.1_linux_x64.tar.gz
sha256: 551f6fc83ea457d62a0d98237cbad105af8d557003051f41f3e7ca7b3f2470eb
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/private-static.yml
Original file line number Diff line number Diff line change
Expand Up @@ -110,7 +110,7 @@ jobs:

- name: Set up uv
if: ${{ inputs.setup_uv }}
uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
version: ${{ inputs.uv_version }}
# uv provisions our pinned tooling here, not the caller's
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/python-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -108,7 +108,7 @@ jobs:

- name: Set up uv and Python
if: ${{ inputs.package_manager == 'uv' && !inputs.use_preinstalled_toolchain }}
uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
version: ${{ inputs.uv_version }}
enable-cache: true
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/qt-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -98,7 +98,7 @@ jobs:
persist-credentials: false

- name: Set up uv
uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
# Pinned, not inherited: setup-uv's `version` defaults to the
# version in pyproject.toml or, absent one, whatever is latest.
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -77,7 +77,7 @@ jobs:
update-environment: false

- name: Set up uv
uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
version: 0.11.30
# setup-uv caches by default. On a publishing workflow that turns the
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/runtime-fixtures-languages.yml
Original file line number Diff line number Diff line change
Expand Up @@ -500,7 +500,7 @@ jobs:
python-version: '3.13'
update-environment: false
- name: Set up uv
uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
# Pinned, not inherited: setup-uv's `version` defaults to the
# version in pyproject.toml or, absent one, whatever is latest.
Expand Down Expand Up @@ -544,7 +544,7 @@ jobs:
python-version: '3.13'
update-environment: false
- name: Set up uv
uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
# Pinned, not inherited: setup-uv's `version` defaults to the
# version in pyproject.toml or, absent one, whatever is latest.
Expand Down Expand Up @@ -601,7 +601,7 @@ jobs:
python-version: '3.13'
update-environment: false
- name: Set up uv
uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
# Pinned, not inherited: setup-uv's `version` defaults to the
# version in pyproject.toml or, absent one, whatever is latest.
Expand Down Expand Up @@ -660,7 +660,7 @@ jobs:
python-version: '3.13'
update-environment: false
- name: Set up uv
uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
# Pinned, not inherited: setup-uv's `version` defaults to the
# version in pyproject.toml or, absent one, whatever is latest.
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/semgrep-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -57,7 +57,7 @@ jobs:
persist-credentials: false

- name: Set up uv
uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
version: 0.11.30
# uv provisions our pinned analyser here, not the caller's
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/sql-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -65,7 +65,7 @@ jobs:
persist-credentials: false

- name: Set up uv
uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
version: 0.11.30
# uv provisions our pinned tooling here, not the caller's
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/zizmor-no-sarif.yml
Original file line number Diff line number Diff line change
Expand Up @@ -56,7 +56,7 @@ jobs:
persist-credentials: false

- name: Set up uv
uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
version: 0.11.30
# Consumer-facing gate. uv provisions our pinned analyser here,
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/zizmor-sarif.yml
Original file line number Diff line number Diff line change
Expand Up @@ -57,7 +57,7 @@ jobs:
persist-credentials: false

- name: Set up uv
uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
version: 0.11.30
# This workflow backs the `zizmor` job, which is in `ci-gate.needs`.
Expand Down
4 changes: 2 additions & 2 deletions catalog/tools.yml
Original file line number Diff line number Diff line change
Expand Up @@ -509,8 +509,8 @@ tools:
name: astral-sh/setup-uv
homepage: "https://github.com/astral-sh/setup-uv"
kind: action
current_version: "v10.1.0"
pin: "astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4"
current_version: "v10.2.0"
pin: "astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7"
used_by:
- .github/workflows/ci.yml
- .github/workflows/dependabot-catalog-convergence.yml
Expand Down
Loading