diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index b8877a78c..ee06b1a8d 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -50,7 +50,7 @@ jobs: run: cargo fmt --all -- --check # Not in taiki-e TOOLS.md; install-action falls back to cargo-binstall # (GitHub Release prebuilt). Do not cargo install. - - uses: taiki-e/install-action@9114bf4d891761788c546334fd37538eae1bf8b3 # v2.87.16 + - uses: taiki-e/install-action@9983c65e42da123ff25d1f78505eb6de315aa172 # v2.87.20 with: tool: ast-grep@0.45.1 - name: ast-grep fixture self-test @@ -61,7 +61,7 @@ jobs: run: ./scripts/ast-grep.sh # Prebuilt cargo-deny — do not cargo install. Pin Action commit (CodeQL). # 0.18.x cannot parse rustsec CVSS 4.0 advisories (2026). - - uses: taiki-e/install-action@9114bf4d891761788c546334fd37538eae1bf8b3 # v2.87.16 + - uses: taiki-e/install-action@9983c65e42da123ff25d1f78505eb6de315aa172 # v2.87.20 with: tool: cargo-deny@0.20.2 - name: cargo deny check @@ -201,7 +201,7 @@ jobs: workspaces: ". -> target/cov" # Prebuilt binary — do not `cargo install` (compiles llvm-cov from crates.io). # Pin commit (CodeQL: unpinned 3rd-party Action tags are not immutable). - - uses: taiki-e/install-action@9114bf4d891761788c546334fd37538eae1bf8b3 # v2.87.16 + - uses: taiki-e/install-action@9983c65e42da123ff25d1f78505eb6de315aa172 # v2.87.20 with: tool: cargo-llvm-cov@0.6.14,cargo-crap@0.4.3 - name: coverage (line gate) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 5a716c1c8..6f57b1e89 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -65,7 +65,7 @@ jobs: uses: dtolnay/rust-toolchain@a5f673d0ba8626c3977bb416a1612774bc82181b # 1.95.0 - name: Initialize CodeQL - uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 + uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 with: languages: ${{ matrix.language }} build-mode: ${{ matrix.build-mode }} @@ -74,6 +74,6 @@ jobs: queries: security-extended - name: Perform CodeQL analysis - uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 + uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 with: category: "/language:${{ matrix.language }}" diff --git a/.github/workflows/fuzz.yml b/.github/workflows/fuzz.yml index 0fd4329ce..5f759309a 100644 --- a/.github/workflows/fuzz.yml +++ b/.github/workflows/fuzz.yml @@ -68,7 +68,7 @@ jobs: - name: clang (libFuzzer) run: sudo apt-get update && sudo apt-get install -y clang - - uses: taiki-e/install-action@9114bf4d891761788c546334fd37538eae1bf8b3 # v2.87.16 + - uses: taiki-e/install-action@9983c65e42da123ff25d1f78505eb6de315aa172 # v2.87.20 with: tool: cargo-fuzz@0.13.2 diff --git a/.github/workflows/mutants.yml b/.github/workflows/mutants.yml index 92f813bbe..ebb58b609 100644 --- a/.github/workflows/mutants.yml +++ b/.github/workflows/mutants.yml @@ -33,7 +33,7 @@ jobs: fetch-depth: 0 persist-credentials: false - uses: dtolnay/rust-toolchain@a5f673d0ba8626c3977bb416a1612774bc82181b # rustc 1.95.0 - - uses: taiki-e/install-action@9114bf4d891761788c546334fd37538eae1bf8b3 # v2.87.16 + - uses: taiki-e/install-action@9983c65e42da123ff25d1f78505eb6de315aa172 # v2.87.20 with: tool: cargo-mutants@27.1.0 - name: previous cursor