diff --git a/.github/workflows/auto-triage.yml b/.github/workflows/auto-triage.yml index f30417b..21072f0 100644 --- a/.github/workflows/auto-triage.yml +++ b/.github/workflows/auto-triage.yml @@ -22,10 +22,10 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - name: Install uv - uses: astral-sh/setup-uv@v5 + uses: astral-sh/setup-uv@v7 with: enable-cache: true diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index ff22473..eaa1514 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -37,10 +37,10 @@ jobs: timeout-minutes: 30 steps: - name: Checkout code - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - name: Install uv - uses: astral-sh/setup-uv@f0ec1fc3b38f5e7cd731bb6ce540c5af426746bb # v5.2.2 + uses: astral-sh/setup-uv@37802adc94f370d6bfd71619e3f0bf239e1f3b78 # v5.2.2 with: enable-cache: true cache-dependency-glob: "uv.lock" @@ -74,15 +74,15 @@ jobs: steps: - name: Checkout code - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - name: Set up Node.js - uses: actions/setup-node@v4 + uses: actions/setup-node@v6 with: node-version: '20' - name: Install uv - uses: astral-sh/setup-uv@f0ec1fc3b38f5e7cd731bb6ce540c5af426746bb # v5.2.2 + uses: astral-sh/setup-uv@37802adc94f370d6bfd71619e3f0bf239e1f3b78 # v5.2.2 with: enable-cache: true cache-dependency-glob: "uv.lock" @@ -102,7 +102,7 @@ jobs: - name: Upload test results if: always() - uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # v4.4.3 + uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0 with: name: test-results-${{ matrix.os }}-py${{ matrix.python-version }} path: tests/results/ @@ -115,10 +115,10 @@ jobs: needs: [lint, test] steps: - name: Checkout code - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - name: Install uv - uses: astral-sh/setup-uv@f0ec1fc3b38f5e7cd731bb6ce540c5af426746bb # v5.2.2 + uses: astral-sh/setup-uv@37802adc94f370d6bfd71619e3f0bf239e1f3b78 # v5.2.2 - name: Set up Python run: uv python install ${{ env.PYTHON_VERSION }} @@ -133,7 +133,7 @@ jobs: run: uv run twine check dist/* - name: Upload build artifacts - uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # v4.4.3 + uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0 with: name: dist-packages path: dist/ @@ -146,15 +146,15 @@ jobs: timeout-minutes: 30 steps: - name: Checkout code - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - name: Set up Node.js - uses: actions/setup-node@v4 + uses: actions/setup-node@v6 with: node-version: '20' - name: Install uv - uses: astral-sh/setup-uv@f0ec1fc3b38f5e7cd731bb6ce540c5af426746bb # v5.2.2 + uses: astral-sh/setup-uv@37802adc94f370d6bfd71619e3f0bf239e1f3b78 # v5.2.2 - name: Set up Python run: uv python install ${{ env.PYTHON_VERSION }} @@ -170,14 +170,14 @@ jobs: run: uv run pytest tests/ --cov=svg2fbf --cov-report=xml --cov-report=html - name: Upload coverage to Codecov - uses: codecov/codecov-action@v5 + uses: codecov/codecov-action@v6 with: file: ./coverage.xml fail_ci_if_error: false verbose: true - name: Upload coverage HTML - uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # v4.4.3 + uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0 with: name: coverage-html path: htmlcov/ diff --git a/.github/workflows/claude-code-review.yml b/.github/workflows/claude-code-review.yml index f9baf14..02ecbba 100644 --- a/.github/workflows/claude-code-review.yml +++ b/.github/workflows/claude-code-review.yml @@ -36,7 +36,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: fetch-depth: 1 diff --git a/.github/workflows/claude.yml b/.github/workflows/claude.yml index 61ad93b..2540df6 100644 --- a/.github/workflows/claude.yml +++ b/.github/workflows/claude.yml @@ -36,7 +36,7 @@ jobs: actions: read # Required for Claude to read CI results on PRs steps: - name: Checkout repository - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: fetch-depth: 1 diff --git a/.github/workflows/e2e.yml b/.github/workflows/e2e.yml index e8a6f55..87eab0e 100644 --- a/.github/workflows/e2e.yml +++ b/.github/workflows/e2e.yml @@ -33,10 +33,10 @@ jobs: steps: - name: Checkout code - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - name: Set up Node.js - uses: actions/setup-node@v4 + uses: actions/setup-node@v6 with: node-version: "20" @@ -48,7 +48,7 @@ jobs: install-dependencies: true - name: Setup uv - uses: astral-sh/setup-uv@f0ec1fc3b38f5e7cd731bb6ce540c5af426746bb # v5.2.2 + uses: astral-sh/setup-uv@37802adc94f370d6bfd71619e3f0bf239e1f3b78 # v5.2.2 with: enable-cache: true tool-bin-dir: ~/.local/bin @@ -81,7 +81,7 @@ jobs: working-directory: tests - name: Run E2E tests - uses: nick-fields/retry@7152eba30c6575329ac0576536151aca5a72780e # v3.0.0 + uses: nick-fields/retry@ad984534de44a9489a53aefd81eb77f87c70dc60 # v4.0.0 env: CI: "true" with: @@ -92,7 +92,7 @@ jobs: - name: Upload test results if: always() - uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # v4.4.3 + uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0 with: name: e2e-test-results path: tests/results/ diff --git a/.github/workflows/quality.yml b/.github/workflows/quality.yml index 38208fc..dd4236b 100644 --- a/.github/workflows/quality.yml +++ b/.github/workflows/quality.yml @@ -32,12 +32,12 @@ jobs: timeout-minutes: 15 steps: - name: Checkout code (full history for base/head refs) - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: fetch-depth: 0 - name: Set up UV - uses: astral-sh/setup-uv@f0ec1fc3b38f5e7cd731bb6ce540c5af426746bb # v5.2.2 + uses: astral-sh/setup-uv@37802adc94f370d6bfd71619e3f0bf239e1f3b78 # v5.2.2 # Ruff: verify formatting & lint (read-only; no --fix) # Why: Use 'uv run' instead of 'uvx' to read project's pyproject.toml config @@ -49,7 +49,7 @@ jobs: # TruffleHog: scan full repository history (fail on verified+unknown secrets) # NOTE: The action automatically adds --fail, --no-update, --github-actions flags - name: Secrets scan (verified+unknown) - uses: trufflesecurity/trufflehog@a450544f0b7c12e99bd78b4f02fe67d5c5e56711 # main + uses: trufflesecurity/trufflehog@6171fa9f6676edf21e15bba41f049b18399d7372 # main with: path: ./ extra_args: > diff --git a/.github/workflows/validate-workflows.yml b/.github/workflows/validate-workflows.yml index a9b1fc1..cee63fc 100644 --- a/.github/workflows/validate-workflows.yml +++ b/.github/workflows/validate-workflows.yml @@ -24,7 +24,7 @@ jobs: timeout-minutes: 5 steps: - name: Checkout code - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - name: Validate YAML syntax run: | diff --git a/tests/package.json b/tests/package.json index a5705fb..c9f0299 100644 --- a/tests/package.json +++ b/tests/package.json @@ -4,7 +4,7 @@ "description": "Node.js test dependencies for svg2fbf", "private": true, "dependencies": { - "puppeteer": "^22.0.0" + "puppeteer": "^24.36.1" }, "engines": { "node": ">=18.0.0"