summaryrefslogtreecommitdiffhomepage
path: root/.github/workflows/pin-github-actions.yml
blob: cb66739931bf1e28673da406b13445ede7d865e2 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
# Pin images used in github actions to a hash instead of a version tag.
name: pin-github-actions
on:
  pull_request:
    branches:
      - main
    paths:
      - ".github/workflows/**"

  workflow_dispatch:

permissions:
  contents: read
  pull-requests: read

concurrency:
  group: ${{ github.workflow }}-${{ github.head_ref || github.run_id }}
  cancel-in-progress: true

jobs:
  run:
    name: pin-github-actions
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
      - name: pin
        run: make pin-github-actions
      - name: check for changed workflow files
        run: git diff --no-ext-diff --exit-code .github/workflows || (echo "Some github actions versions need pinning, run make pin-github-actions."; exit 1)