alamb commented on code in PR #16964:
URL: https://github.com/apache/datafusion/pull/16964#discussion_r2240605914


##########
.github/workflows/dev.yml:
##########
@@ -27,15 +27,15 @@ jobs:
     runs-on: ubuntu-latest
     name: Check License Header
     steps:
-      - uses: actions/checkout@v4
-      - uses: korandoru/hawkeye@v6
+      - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683  # 
v4.2.2
+      - uses: korandoru/hawkeye@cdc68d9c8ace500aefcd8f4dd39b915cd06305dd  # 
v6.1.1

Review Comment:
   ✅  https://github.com/korandoru/hawkeye/releases/tag/v6.1.1



##########
.github/workflows/docs.yaml:
##########
@@ -32,16 +32,16 @@ jobs:
     runs-on: ubuntu-latest
     steps:
       - name: Checkout docs sources
-        uses: actions/checkout@v4
+        uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683  # 
v4.2.2
 
       - name: Checkout asf-site branch
-        uses: actions/checkout@v4
+        uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683  # 
v4.2.2
         with:
           ref: asf-site
           path: asf-site
 
       - name: Setup Python
-        uses: actions/setup-python@v5
+        uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065  # 
v5.6.0

Review Comment:
   https://github.com/actions/setup-python/releases/tag/v5.6.0



##########
.github/workflows/audit.yml:
##########
@@ -38,7 +38,7 @@ jobs:
   security_audit:
     runs-on: ubuntu-latest
     steps:
-      - uses: actions/checkout@v4
+      - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683  # 
v4.2.2

Review Comment:
   I verified this has matches the sha
   
   https://github.com/actions/checkout/releases/tag/v4.2.2



##########
.github/workflows/rust.yml:
##########
@@ -46,13 +46,13 @@ jobs:
     container:
       image: amd64/rust
     steps:
-      - uses: actions/checkout@v4
+      - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683  # 
v4.2.2
       - name: Setup Rust toolchain
         uses: ./.github/actions/setup-builder
         with:
           rust-version: stable
       - name: Rust Dependency Cache
-        uses: Swatinem/rust-cache@v2
+        uses: Swatinem/rust-cache@98c8021b550208e191a6a3145459bfc9fb29c4c0  # 
v2.8.0

Review Comment:
   https://github.com/Swatinem/rust-cache/releases/tag/v2



##########
.github/workflows/stale.yml:
##########
@@ -27,7 +27,7 @@ jobs:
       issues: write
       pull-requests: write
     steps:
-      - uses: actions/stale@v9
+      - uses: actions/stale@5bef64f19d7facfb25b37b414482c7164d639639  # v9.1.0

Review Comment:
   https://github.com/actions/stale/releases/tag/v9.1.0



##########
.github/workflows/dev.yml:
##########
@@ -27,15 +27,15 @@ jobs:
     runs-on: ubuntu-latest
     name: Check License Header
     steps:
-      - uses: actions/checkout@v4
-      - uses: korandoru/hawkeye@v6
+      - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683  # 
v4.2.2
+      - uses: korandoru/hawkeye@cdc68d9c8ace500aefcd8f4dd39b915cd06305dd  # 
v6.1.1
 
   prettier:
     name: Use prettier to check formatting of documents
     runs-on: ubuntu-latest
     steps:
-      - uses: actions/checkout@v4
-      - uses: actions/setup-node@v4
+      - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683  # 
v4.2.2
+      - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020  # 
v4.4.0

Review Comment:
   https://github.com/actions/setup-node/releases/tag/v4.4.0 



##########
.github/workflows/pr_comment_commands.yml:
##########
@@ -34,7 +34,7 @@ jobs:
     if: ${{ github.event_name == 'issue_comment' && 
github.event.issue.pull_request && contains(github.event.comment.body, 'Run 
extended tests') }}
     steps:
       - name: Dispatch extended tests for a PR branch with comment
-        uses: actions/github-script@v7
+        uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea  
# v7.0.1

Review Comment:
   https://github.com/actions/github-script/releases/tag/v7.0.1



##########
.github/workflows/extended.yml:
##########
@@ -80,13 +80,13 @@ jobs:
     runs-on: ubuntu-latest
     # note: do not use amd/rust container to preserve disk space
     steps:
-      - uses: actions/checkout@v4
+      - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683  # 
v4.2.2
         with:
           ref: ${{ github.event.inputs.pr_head_sha }} # will be empty if 
triggered by push
           submodules: true
           fetch-depth: 1
       - name: Free Disk Space (Ubuntu)
-        uses: 
jlumbroso/free-disk-space@54081f138730dfa15788a46383842cd2f914a1be
+        uses: 
jlumbroso/free-disk-space@54081f138730dfa15788a46383842cd2f914a1be  # v1.3.1

Review Comment:
   https://github.com/jlumbroso/free-disk-space/releases/tag/v1.3.1



##########
.github/workflows/labeler.yml:
##########
@@ -39,14 +39,14 @@ jobs:
       contents: read
       pull-requests: write
     steps:
-      - uses: actions/checkout@v4
+      - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683  # 
v4.2.2
 
       - name: Assign GitHub labels
         if: |
           github.event_name == 'pull_request_target' &&
             (github.event.action == 'opened' ||
              github.event.action == 'synchronize')
-        uses: actions/labeler@v5.0.0
+        uses: actions/labeler@8558fd74291d67161a8a78ce36a881fa63b766a9  # 
v5.0.0

Review Comment:
   https://github.com/actions/labeler/releases/tag/v5.0.0



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: github-unsubscr...@datafusion.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org


---------------------------------------------------------------------
To unsubscribe, e-mail: github-unsubscr...@datafusion.apache.org
For additional commands, e-mail: github-h...@datafusion.apache.org

Reply via email to