chore: pin dependencies (actions, docker, cli) (#29460)

This commit is contained in:
Michael Geers 2026-05-03 12:12:14 +02:00 • committed by GitHub
parent 002e55f63b
commit f06c09b060
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
8 changed files with 28 additions and 22 deletions

View file

@ -6,3 +6,9 @@ updates:
interval: "monthly"
labels:
- "infrastructure"
- package-ecosystem: "docker"
directory: "/"
schedule:
interval: "monthly"
labels:
- "infrastructure"

View file

@ -148,7 +148,7 @@ jobs:
- run: mkdir dist && touch dist/empty
- name: Lint
uses: golangci/golangci-lint-action@v9
uses: golangci/golangci-lint-action@1e7e51e771db61008b38414a730f564565cf7c20 # v9
with:
version: latest
args: --timeout 5m

View file

@ -29,7 +29,7 @@ jobs:
run: make install docs
- name: Deploy to docs repo
uses: peaceiris/actions-gh-pages@v4
uses: peaceiris/actions-gh-pages@4f9cc6602d3f66b9c108549d475ec49e8ef4d45e # v4
with:
personal_token: ${{ secrets.DOCS_DEPLOY_TOKEN }}
publish_dir: ./templates/docs
@ -61,7 +61,7 @@ jobs:
cp ./server/openapi.yaml ./openapi-deploy/openapi.yaml
- name: Deploy OpenAPI spec to docs repo
uses: peaceiris/actions-gh-pages@v4
uses: peaceiris/actions-gh-pages@4f9cc6602d3f66b9c108549d475ec49e8ef4d45e # v4
with:
personal_token: ${{ secrets.DOCS_DEPLOY_TOKEN }}
publish_dir: ./openapi-deploy

View file

@ -66,17 +66,17 @@ jobs:
key: ${{ runner.os }}-${{ github.sha }}-dist
- name: Login
uses: docker/login-action@v4
uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4
with:
username: ${{ secrets.DOCKER_USER }}
password: ${{ secrets.DOCKER_PASS }}
- name: Setup Buildx
uses: docker/setup-buildx-action@v4
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4
- name: Define tags
id: meta
uses: docker/metadata-action@v6
uses: docker/metadata-action@030e881283bb7a6894de51c315a6bfe6a94e05cf # v6
with:
images: evcc/evcc
tags: |
@ -84,7 +84,7 @@ jobs:
type=raw,value=nightly.{{date 'YYYYMMDD'}}-{{sha}}
- name: Publish
uses: docker/build-push-action@v7
uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v7
with:
context: .
platforms: linux/amd64,linux/arm64,linux/arm/v6
@ -175,7 +175,7 @@ jobs:
key: ${{ runner.os }}-${{ github.sha }}-dist
- name: Create nightly build
uses: goreleaser/goreleaser-action@v7
uses: goreleaser/goreleaser-action@1a80836c5c9d9e5755a25cb59ec6f45a3b5f41a8 # v7
with:
version: '~> v2'
args: --snapshot -f .goreleaser-nightly.yml --clean
@ -187,7 +187,7 @@ jobs:
python-version: 3.12
- name: Install Cloudsmith CLI
run: pip install --upgrade cloudsmith-cli
run: pip install cloudsmith-cli==1.16.0
- name: Publish .deb to Cloudsmith
env:

View file

@ -31,23 +31,23 @@ jobs:
persist-credentials: false
- name: Login
uses: docker/login-action@v4
uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4
with:
username: ${{ secrets.DOCKER_USER }}
password: ${{ secrets.DOCKER_PASS }}
- name: Setup Buildx
uses: docker/setup-buildx-action@v4
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4
- name: Meta
id: meta
uses: docker/metadata-action@v6
uses: docker/metadata-action@030e881283bb7a6894de51c315a6bfe6a94e05cf # v6
with:
images: |
evcc/evcc
- name: Publish
uses: docker/build-push-action@v7
uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v7
with:
context: .
platforms: linux/amd64,linux/arm64,linux/arm/v6
@ -103,7 +103,7 @@ jobs:
# run: make image-rootfs
- name: Create Github Release
uses: goreleaser/goreleaser-action@v7
uses: goreleaser/goreleaser-action@1a80836c5c9d9e5755a25cb59ec6f45a3b5f41a8 # v7
with:
version: '~> v2'
args: release --clean
@ -116,7 +116,7 @@ jobs:
python-version: 3.12
- name: Install Cloudsmith CLI
run: pip install --upgrade cloudsmith-cli
run: pip install cloudsmith-cli==1.16.0
- name: Publish .deb to Cloudsmith
env:
@ -138,7 +138,7 @@ jobs:
- uses: actions/checkout@v6
with:
persist-credentials: false
- uses: superfly/flyctl-actions/setup-flyctl@master
- uses: superfly/flyctl-actions/setup-flyctl@ed8efb33836e8b2096c7fd3ba1c8afe303ebbff1 # master
- run: flyctl deploy --local-only --config packaging/fly.toml
hassio:
@ -152,7 +152,7 @@ jobs:
steps:
- name: Checkout
uses: actions/checkout@master
uses: actions/checkout@v6
with:
repository: evcc-io/hassio-addon
token: ${{ secrets.HASSIO_DEPLOY_TOKEN }}

View file

@ -21,7 +21,7 @@ jobs:
- uses: actions/checkout@v6
with:
persist-credentials: false
- uses: nwisbeta/validate-yaml-schema@v2.0.0
- uses: nwisbeta/validate-yaml-schema@c3734e647d2a3beb98b9132330067e900fdbd1a2 # v2.0.0
with:
yamlSchemasJson: |
{

View file

@ -32,7 +32,7 @@ jobs:
run: rm templates/evcc.io/.gitignore
- name: Deploy to evcc.io repo
uses: peaceiris/actions-gh-pages@v4
uses: peaceiris/actions-gh-pages@4f9cc6602d3f66b9c108549d475ec49e8ef4d45e # v4
with:
personal_token: ${{ secrets.WEBSITE_DEPLOY_TOKEN }}
publish_dir: ./templates/evcc.io/

View file

@ -1,5 +1,5 @@
# STEP 1 build ui
FROM --platform=$BUILDPLATFORM node:24-alpine AS node
FROM --platform=$BUILDPLATFORM node:24-alpine@sha256:d1b3b4da11eefd5941e7f0b9cf17783fc99d9c6fc34884a665f40a06dbdfc94f AS node
RUN apk update && apk add --no-cache make
@ -21,7 +21,7 @@ RUN make ui
# STEP 2 build executable binary
FROM --platform=$BUILDPLATFORM golang:1.26-alpine AS builder
FROM --platform=$BUILDPLATFORM golang:1.26-alpine@sha256:f85330846cde1e57ca9ec309382da3b8e6ae3ab943d2739500e08c86393a21b1 AS builder
# Install git + SSL ca certificates.
# Git is required for fetching the dependencies.
@ -68,7 +68,7 @@ RUN --mount=type=cache,target=${GOCACHE} --mount=type=cache,target=${GOMODCACHE}
# STEP 3 build a small image including module support
FROM alpine:3.22
FROM alpine:3.22@sha256:310c62b5e7ca5b08167e4384c68db0fd2905dd9c7493756d356e893909057601
WORKDIR /app