summaryrefslogtreecommitdiffhomepage
path: root/.github/workflows/pin-github-actions.yml
blob: 7c1816d134cd6a44472ac9d9adf81dce1cbb8a91 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
# Pin images used in github actions to a hash instead of a version tag.
name: pin-github-actions
on:
  pull_request:
    branches:
      - main
    paths:
      - ".github/workflows/**"

  workflow_dispatch:

permissions:
  contents: read
  pull-requests: read

concurrency:
  group: ${{ github.workflow }}-${{ github.head_ref || github.run_id }}
  cancel-in-progress: true

jobs:
  run:
    name: pin-github-actions
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
      - name: pin
        run: make pin-github-actions
      - name: check for changed workflow files
        run: git diff --no-ext-diff --exit-code .github/workflows || (echo "Some github actions versions need pinning, run make pin-github-actions."; exit 1)