This is an automated email from the ASF dual-hosted git repository.

davidzollo pushed a commit to branch ci-fix-pin-docker-actions-20260917
in repository https://gitbox.apache.org/repos/asf/seatunnel.git

commit 2b924f0498803937cf01768b2a38cd2a050ccc06
Author: David Zollo <[email protected]>
AuthorDate: Wed Sep 16 22:29:19 2026 -0400

    [Fix][CI] Pin Docker publishing actions to approved SHAs
---
 .github/workflows/publish-docker.yaml | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/.github/workflows/publish-docker.yaml 
b/.github/workflows/publish-docker.yaml
index 5fb86b7bc3..b02c0b637c 100644
--- a/.github/workflows/publish-docker.yaml
+++ b/.github/workflows/publish-docker.yaml
@@ -57,14 +57,14 @@ jobs:
           distribution: 'adopt'
 
       - name: Log in to the Container registry
-        uses: docker/login-action@v3
+        uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # 
v4.6.0
         with:
           username: ${{ env.DOCKER_USERNAME }}
           password: ${{ env.DOCKER_PASSWORD }}
       - name: Set up QEMU
-        uses: docker/setup-qemu-action@v3
+        uses: 
docker/setup-qemu-action@1f40c72289eff860ee54a304f1438e3cff362e0a # v4.3.0
       - name: Set up Docker Buildx
-        uses: docker/setup-buildx-action@v3
+        uses: 
docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
       - name: Build and push docker images
         env:
           MAVEN_OPTS: -Xmx4096m
@@ -79,4 +79,4 @@ jobs:
           -D"skip.spotless"=true \
           -Dmaven.deploy.skip \
           --no-snapshot-updates \
-          -Pdocker,seatunnel
\ No newline at end of file
+          -Pdocker,seatunnel

Reply via email to