diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 7e468916..5017c1c9 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -25,7 +25,7 @@ jobs: with: fetch-depth: 0 # gates diff against git merge-base persist-credentials: false - - uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 + - uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 with: python-version: ${{ matrix.python }} - run: uv sync --frozen diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 105d53dd..8c21da31 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -58,7 +58,7 @@ jobs: python-version: "3.13" - name: Initialize CodeQL - uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 + uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 with: languages: ${{ matrix.language }} # Neither language compiles: the source is what is analysed. @@ -66,4 +66,4 @@ jobs: config-file: ./.github/codeql/codeql-config.yml - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 + uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 058c2606..cfb9d9e5 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -28,7 +28,7 @@ jobs: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - - uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 + - uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 with: enable-cache: false - run: uv sync --frozen @@ -117,7 +117,7 @@ jobs: # hand-kept list of what the project needs goes stale the first time # the wheel gains package data. Same rule here as locally, or the # published image differs from the built one in a way nothing checks. - - uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 + - uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 with: enable-cache: false - run: uv sync --frozen diff --git a/.github/workflows/serve-bundle.yml b/.github/workflows/serve-bundle.yml index 80b7bfb5..61022a7e 100644 --- a/.github/workflows/serve-bundle.yml +++ b/.github/workflows/serve-bundle.yml @@ -30,7 +30,7 @@ jobs: run: cd web && npm ci && npm run build - name: vendored bundle matches the fresh build run: git diff --exit-code -- src/torve/_web - - uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 + - uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 with: enable-cache: false - run: uv sync --frozen --extra serve