Skip to content

Commit d67c42f

Browse files
authored
fix(ci): Possible security issues (#2180)
1 parent c72bdee commit d67c42f

File tree

3 files changed

+12
-5
lines changed

3 files changed

+12
-5
lines changed

.github/workflows/lint.yml

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,9 @@ on:
44
branches:
55
- main
66
pull_request:
7+
permissions:
8+
contents: read
9+
pull-requests: read
710
jobs:
811
lint:
912
runs-on: buildjet-4vcpu-ubuntu-2204
@@ -13,7 +16,7 @@ jobs:
1316
- name: Checkout
1417
uses: actions/checkout@v4
1518
- name: pnpm setup
16-
uses: pnpm/action-setup@v4
19+
uses: pnpm/action-setup@a7487c7e89a18df4991f7f222e4898a00d66ddda
1720
- name: pnpm Cache
1821
uses: buildjet/cache@v4
1922
with:

.github/workflows/tests.yml

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,9 @@ on:
44
branches:
55
- main
66
pull_request:
7+
permissions:
8+
contents: read
9+
pull-requests: read
710
jobs:
811
build:
912
runs-on: buildjet-4vcpu-ubuntu-2204
@@ -23,7 +26,7 @@ jobs:
2326
pnpm config set script-shell "/usr/bin/bash"
2427
2528
- name: pnpm Cache
26-
uses: buildjet/cache@v4
29+
uses: buildjet/cache@3e70d19e31d6a8030aeddf6ed8dbe601f94d09f4
2730
with:
2831
path: |
2932
~/.pnpm-store
@@ -38,7 +41,7 @@ jobs:
3841
run: pnpm install --frozen-lockfile
3942

4043
- name: turborepo Cache
41-
uses: buildjet/cache@v4
44+
uses: buildjet/cache@3e70d19e31d6a8030aeddf6ed8dbe601f94d09f4
4245
with:
4346
path: |
4447
.turbo
@@ -63,7 +66,7 @@ jobs:
6366
corepack prepare [email protected] --activate
6467
6568
- name: Restore dependencies
66-
uses: buildjet/cache@v4
69+
uses: buildjet/cache@3e70d19e31d6a8030aeddf6ed8dbe601f94d09f4
6770
with:
6871
path: |
6972
~/.pnpm-store
@@ -72,7 +75,7 @@ jobs:
7275
key: ${{ runner.os }}-pnpm-${{ hashFiles('**/pnpm-lock.yaml') }}
7376

7477
- name: turborepo Cache
75-
uses: buildjet/cache@v4
78+
uses: buildjet/cache@3e70d19e31d6a8030aeddf6ed8dbe601f94d09f4
7679
with:
7780
path: |
7881
.turbo

.github/workflows/version.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,7 @@ on:
55
branches:
66
- main
77

8+
89
concurrency: ${{ github.workflow }}-${{ github.ref }}
910

1011
jobs:

0 commit comments

Comments
 (0)