diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 669daaa3..fa30b10f 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -484,7 +484,7 @@ jobs: cache: npm - run: npm ci - run: npm run build - - uses: docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v3 + - uses: docker/setup-qemu-action@99012661954931238ded8c8b007157a8430204e1 # v4.4.0 - name: Tag the checkout so install.sh has a pinned version to clone run: | set -euo pipefail diff --git a/scripts/check-exact-head-ci.mjs b/scripts/check-exact-head-ci.mjs index dbc7d2cf..b3f624ee 100644 --- a/scripts/check-exact-head-ci.mjs +++ b/scripts/check-exact-head-ci.mjs @@ -40,7 +40,7 @@ const CI_WORKFLOW_FILE_PATH = fileURLToPath(new URL(`../${CI_WORKFLOW_PATH}`, im // shell command; without this lock replacing every job body with `true` would // still look like a real successful run. Update deliberately with the CI // workflow when its reviewed job contract changes. -export const EXPECTED_CI_WORKFLOW_SHA256 = 'e82d9cdc4de7c5acad722fb887d41535b6c38ebd9cc057edc0df70c07f45ef00'; +export const EXPECTED_CI_WORKFLOW_SHA256 = '57d776e9b87a00ca7a11643d6ccb4098c2c6b8d82b9614c62e9e946456e81819'; // Fixed rather than inferred from returned jobs: absence must fail rather // than define itself away. `lint` only runs for pull requests and is therefore