diff --git a/.github/workflows/backfill-release-assets.yml b/.github/workflows/backfill-release-assets.yml index d5c7f65c3..1c34b6b21 100644 --- a/.github/workflows/backfill-release-assets.yml +++ b/.github/workflows/backfill-release-assets.yml @@ -29,7 +29,7 @@ jobs: persist-credentials: false - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false diff --git a/.github/workflows/build-and-test.yml b/.github/workflows/build-and-test.yml index e00ff0c8f..00ac6d988 100644 --- a/.github/workflows/build-and-test.yml +++ b/.github/workflows/build-and-test.yml @@ -240,7 +240,7 @@ jobs: - name: Set up Go if: needs.changes.outputs.code == 'true' - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: true @@ -296,7 +296,7 @@ jobs: fetch-depth: 0 - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: true @@ -334,7 +334,7 @@ jobs: path: benchmark-base - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: true diff --git a/.github/workflows/build-release-candidate.yml b/.github/workflows/build-release-candidate.yml index 95f915092..45f219a35 100644 --- a/.github/workflows/build-release-candidate.yml +++ b/.github/workflows/build-release-candidate.yml @@ -282,7 +282,7 @@ jobs: persist-credentials: false - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false @@ -386,7 +386,7 @@ jobs: persist-credentials: false - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false @@ -462,7 +462,7 @@ jobs: - name: Submit SignPath Authenticode request if: ${{ inputs.windows_signing_backend == 'signpath' }} id: signpath - uses: signpath/github-action-submit-signing-request@c92b958760219087e01f8d67a1669ed57afe2627 # v2 + uses: signpath/github-action-submit-signing-request@f6d04783b4569d051e0c80105fe66e82819d0092 # v3.0 with: api-token: ${{ secrets.SIGNPATH_API_TOKEN }} organization-id: ${{ vars.SIGNPATH_ORGANIZATION_ID }} @@ -702,7 +702,7 @@ jobs: test "$(git rev-parse HEAD)" = "${GITHUB_SHA}" - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false diff --git a/.github/workflows/canonical-governance.yml b/.github/workflows/canonical-governance.yml index c606ebaaa..fe6db7666 100644 --- a/.github/workflows/canonical-governance.yml +++ b/.github/workflows/canonical-governance.yml @@ -31,7 +31,7 @@ jobs: path: repos/pulse - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: repos/pulse/go.mod cache: true diff --git a/.github/workflows/canonical-private-governance.yml b/.github/workflows/canonical-private-governance.yml index 24df2f4f0..a8f745448 100644 --- a/.github/workflows/canonical-private-governance.yml +++ b/.github/workflows/canonical-private-governance.yml @@ -59,7 +59,7 @@ jobs: path: repos/pulse-mobile - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: repos/pulse/go.mod cache: false diff --git a/.github/workflows/compile-release-payload.yml b/.github/workflows/compile-release-payload.yml index 7799807bb..f59a08da3 100644 --- a/.github/workflows/compile-release-payload.yml +++ b/.github/workflows/compile-release-payload.yml @@ -59,7 +59,7 @@ jobs: test "$(git rev-parse HEAD)" = "${EXPECTED_SOURCE_SHA}" - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false @@ -134,7 +134,7 @@ jobs: ref: ${{ inputs.source_sha }} - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false diff --git a/.github/workflows/create-release.yml b/.github/workflows/create-release.yml index 7bb147e55..375f89a2d 100644 --- a/.github/workflows/create-release.yml +++ b/.github/workflows/create-release.yml @@ -536,7 +536,7 @@ jobs: cp -r frontend-modern/dist internal/api/frontend-modern/ - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false @@ -582,7 +582,7 @@ jobs: cp -r frontend-modern/dist internal/api/frontend-modern/ - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: true @@ -1343,7 +1343,7 @@ jobs: persist-credentials: false - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false diff --git a/.github/workflows/eval-model-matrix.yml b/.github/workflows/eval-model-matrix.yml index 3bde95360..6f7393799 100644 --- a/.github/workflows/eval-model-matrix.yml +++ b/.github/workflows/eval-model-matrix.yml @@ -40,7 +40,7 @@ jobs: persist-credentials: false - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false diff --git a/.github/workflows/issue-version-label-sync.yml b/.github/workflows/issue-version-label-sync.yml index 772174265..701da9886 100644 --- a/.github/workflows/issue-version-label-sync.yml +++ b/.github/workflows/issue-version-label-sync.yml @@ -32,7 +32,7 @@ jobs: sparse-checkout-cone-mode: false - name: Sync issue version metadata - uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0 + uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: github-token: ${{ steps.triage-token.outputs.token }} script: | diff --git a/.github/workflows/patrol-qualification-regression.yml b/.github/workflows/patrol-qualification-regression.yml index ce857e1b5..bc590997a 100644 --- a/.github/workflows/patrol-qualification-regression.yml +++ b/.github/workflows/patrol-qualification-regression.yml @@ -50,7 +50,7 @@ jobs: persist-credentials: false - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod diff --git a/.github/workflows/qualify-secure-runtime-release.yml b/.github/workflows/qualify-secure-runtime-release.yml index fedb8f2bb..92f9e3f5a 100644 --- a/.github/workflows/qualify-secure-runtime-release.yml +++ b/.github/workflows/qualify-secure-runtime-release.yml @@ -86,7 +86,7 @@ jobs: python3 scripts/write_github_output.py line_ref "origin/${required_branch}" - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: true diff --git a/.github/workflows/reclaim-closed-pr-capacity.yml b/.github/workflows/reclaim-closed-pr-capacity.yml index f53ea018c..1022651e8 100644 --- a/.github/workflows/reclaim-closed-pr-capacity.yml +++ b/.github/workflows/reclaim-closed-pr-capacity.yml @@ -26,7 +26,7 @@ jobs: sparse-checkout-cone-mode: false - name: Cancel unfinished runs for the closed head - uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0 + uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: script: | const cleanup = require(`${process.env.GITHUB_WORKSPACE}/.github/scripts/reclaim-closed-pr-capacity.cjs`); diff --git a/.github/workflows/release-dry-run.yml b/.github/workflows/release-dry-run.yml index 9faa6263f..145838976 100644 --- a/.github/workflows/release-dry-run.yml +++ b/.github/workflows/release-dry-run.yml @@ -314,7 +314,7 @@ jobs: sudo apt-get install -y docker-compose - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false diff --git a/.github/workflows/root-pair-diagnostic.yml b/.github/workflows/root-pair-diagnostic.yml index bc8659565..5fd3aeb47 100644 --- a/.github/workflows/root-pair-diagnostic.yml +++ b/.github/workflows/root-pair-diagnostic.yml @@ -33,7 +33,7 @@ jobs: with: persist-credentials: false fetch-depth: 0 - - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version: '1.26.8' cache: false diff --git a/.github/workflows/security-scan.yml b/.github/workflows/security-scan.yml index 9cfd24ec1..c7862e486 100644 --- a/.github/workflows/security-scan.yml +++ b/.github/workflows/security-scan.yml @@ -38,7 +38,7 @@ jobs: - name: Set up Go if: ${{ github.event.schedule != '17 */6 * * *' }} - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod @@ -377,7 +377,7 @@ jobs: persist-credentials: false - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod @@ -404,7 +404,7 @@ jobs: persist-credentials: false - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod diff --git a/.github/workflows/signpath-test-signing.yml b/.github/workflows/signpath-test-signing.yml index 054815e6e..ab712b160 100644 --- a/.github/workflows/signpath-test-signing.yml +++ b/.github/workflows/signpath-test-signing.yml @@ -31,7 +31,7 @@ jobs: persist-credentials: false - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false @@ -104,7 +104,7 @@ jobs: - name: Submit SignPath test-signing request id: signpath - uses: signpath/github-action-submit-signing-request@c92b958760219087e01f8d67a1669ed57afe2627 # v2 + uses: signpath/github-action-submit-signing-request@f6d04783b4569d051e0c80105fe66e82819d0092 # v3.0 with: api-token: ${{ secrets.SIGNPATH_API_TOKEN }} organization-id: ${{ vars.SIGNPATH_ORGANIZATION_ID }} diff --git a/.github/workflows/test-e2e.yml b/.github/workflows/test-e2e.yml index 652dede6c..0c2945067 100644 --- a/.github/workflows/test-e2e.yml +++ b/.github/workflows/test-e2e.yml @@ -92,7 +92,7 @@ jobs: frontend-modern/package-lock.json internal/cloudcp/portal/frontend/package-lock.json - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod - name: Install locked dependencies diff --git a/.github/workflows/unified-agent-native.yml b/.github/workflows/unified-agent-native.yml index b4979d4c5..ca020f2c3 100644 --- a/.github/workflows/unified-agent-native.yml +++ b/.github/workflows/unified-agent-native.yml @@ -79,7 +79,7 @@ jobs: persist-credentials: false - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: true @@ -186,7 +186,7 @@ jobs: persist-credentials: false - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: true diff --git a/.github/workflows/update-demo-server.yml b/.github/workflows/update-demo-server.yml index 663be34f7..c45738517 100644 --- a/.github/workflows/update-demo-server.yml +++ b/.github/workflows/update-demo-server.yml @@ -301,7 +301,7 @@ jobs: - name: Set up Go if: inputs.verify_only != true - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false diff --git a/.github/workflows/uuid-layout-diagnostic.yml b/.github/workflows/uuid-layout-diagnostic.yml index 3ad2deb39..0a160849f 100644 --- a/.github/workflows/uuid-layout-diagnostic.yml +++ b/.github/workflows/uuid-layout-diagnostic.yml @@ -33,7 +33,7 @@ jobs: with: persist-credentials: false fetch-depth: 0 - - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version: '1.26.7' cache: false diff --git a/scripts/check_workflow_trust.py b/scripts/check_workflow_trust.py index 97f2c03a5..dded0a208 100644 --- a/scripts/check_workflow_trust.py +++ b/scripts/check_workflow_trust.py @@ -155,7 +155,7 @@ GENERATED_CODE_ACTION_INPUTS = { SAFE_PULL_REQUEST_TARGET_WORKFLOW = "reclaim-closed-pr-capacity.yml" SAFE_PULL_REQUEST_TARGET_ACTIONS = ( "actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1", - "actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd", + "actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3", ) # v7.0.1 includes checkout's fail-closed fork-PR protection for privileged # pull_request_target and workflow_run events. Keep this exact-pin allowlist @@ -172,7 +172,7 @@ REVIEWED_NODE24_ACTION_PINS = { {"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c"} ), "actions/github-script@": frozenset( - {"ed597411d8f924073f98dfc5c65a23a2325f34cd"} + {"3a2844b7e9c422d3c10d287c895573f7108da1b3"} ), } WRITE_CREDENTIAL_RATIONALE = "# required: authenticated git writes" diff --git a/scripts/installtests/build_release_assets_test.go b/scripts/installtests/build_release_assets_test.go index 467324fcc..8c2678b9a 100644 --- a/scripts/installtests/build_release_assets_test.go +++ b/scripts/installtests/build_release_assets_test.go @@ -1427,7 +1427,7 @@ func TestBackfillReleaseWorkflowRepairsPublishedAssetsWithoutRebuilds(t *testing `contents: write`, `runs-on: ubuntu-24.04`, `uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1`, - `uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0`, + `uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0`, `SYFT_VERSION="1.42.4"`, `SYFT_ARCHIVE="syft_${SYFT_VERSION}_linux_amd64.tar.gz"`, `SYFT_SHA256="590650c2743b83f327d1bf9bec64f6f83b7fec504187bb84f500c862bf8f2a0f"`, @@ -1747,7 +1747,7 @@ func TestReleaseCandidateRequiresPlatformNativeAgentSigning(t *testing.T) { `sign-windows-agent:`, `collect-windows-signing:`, `windows_signing_backend:`, - `signpath/github-action-submit-signing-request@c92b958760219087e01f8d67a1669ed57afe2627 # v2`, + `signpath/github-action-submit-signing-request@f6d04783b4569d051e0c80105fe66e82819d0092 # v3.0`, `github-artifact-id: ${{ steps.upload-unsigned-windows.outputs.artifact-id }}`, `wait-for-completion: false`, `windows-signing-request.json`, @@ -2279,7 +2279,7 @@ func TestUpdateDemoWorkflowUsesGovernedNetworkPath(t *testing.T) { `Waiting for activated release assets to be available`, `bash /tmp/pulse-install.sh --version "$TAG"`, `Refuse mutation during verification-only checks`, - `uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0`, + `uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0`, `go run ./scripts/release_update_key.go public-key-ssh`, `sed -i "s|^PINNED_RELEASE_SSH_PUBLIC_KEY=.*|PINNED_RELEASE_SSH_PUBLIC_KEY=\"${TRUSTED_SSH_PUBLIC_KEY}\"|" /tmp/pulse-install.sh`, `Verify target host identity`, diff --git a/scripts/release_control/action_consumer_manifests.json b/scripts/release_control/action_consumer_manifests.json index 114486075..876faf91f 100644 --- a/scripts/release_control/action_consumer_manifests.json +++ b/scripts/release_control/action_consumer_manifests.json @@ -165,8 +165,8 @@ } }, "signpath/github-action-submit-signing-request": { - "sha": "c92b958760219087e01f8d67a1669ed57afe2627", - "manifest_sha256": "d0b52fdfa234d87c1ff4d21c06a91d2b6e0dd45e1a8866ad3b58cbdeb9aef326", + "sha": "f6d04783b4569d051e0c80105fe66e82819d0092", + "manifest_sha256": "9afe14756752bb0b43421bf94e7cebdc3fead29765be4f07fbc60d82421ebc23", "inputs": [ "api-token", "artifact-configuration-slug", diff --git a/scripts/release_control/release_promotion_policy_test.py b/scripts/release_control/release_promotion_policy_test.py index ffe55f628..09df57eba 100644 --- a/scripts/release_control/release_promotion_policy_test.py +++ b/scripts/release_control/release_promotion_policy_test.py @@ -1632,7 +1632,7 @@ class ReleasePromotionPolicyTest(unittest.TestCase): workflow, ) self.assertIn( - "signpath/github-action-submit-signing-request@c92b958760219087e01f8d67a1669ed57afe2627 # v2", + "signpath/github-action-submit-signing-request@f6d04783b4569d051e0c80105fe66e82819d0092 # v3.0", workflow, ) self.assertIn("signedArtifactsPublished = $false", workflow) @@ -2008,7 +2008,7 @@ class ReleasePromotionPolicyTest(unittest.TestCase): self.assertIn("windows_signing_backend: signpath", content) self.assertIn('if [[ "$REQUIRE_WINDOWS_SIGNING" == "true" ]]', candidate_workflow) self.assertIn("inputs.require_windows_signing", candidate_workflow) - self.assertIn("signpath/github-action-submit-signing-request@c92b958760219087e01f8d67a1669ed57afe2627 # v2", candidate_workflow) + self.assertIn("signpath/github-action-submit-signing-request@f6d04783b4569d051e0c80105fe66e82819d0092 # v3.0", candidate_workflow) self.assertIn("github-artifact-id: ${{ steps.upload-unsigned-windows.outputs.artifact-id }}", candidate_workflow) self.assertIn("windows-signing-evidence.json", candidate_workflow) for signpath_setting in (