From f06c09b060e3582adafd71c51a72520816bfd015 Mon Sep 17 00:00:00 2001 From: Michael Geers Date: Sun, 3 May 2026 12:12:14 +0200 Subject: [PATCH] chore: pin dependencies (actions, docker, cli) (#29460) --- .github/dependabot.yml | 6 ++++++ .github/workflows/default.yml | 2 +- .github/workflows/documentation.yml | 4 ++-- .github/workflows/nightly.yml | 12 ++++++------ .github/workflows/release.yml | 16 ++++++++-------- .github/workflows/schema.yml | 2 +- .github/workflows/website.yml | 2 +- Dockerfile | 6 +++--- 8 files changed, 28 insertions(+), 22 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 9a0107604..8d473e712 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -6,3 +6,9 @@ updates: interval: "monthly" labels: - "infrastructure" + - package-ecosystem: "docker" + directory: "/" + schedule: + interval: "monthly" + labels: + - "infrastructure" diff --git a/.github/workflows/default.yml b/.github/workflows/default.yml index 5894db11a..3c134457d 100644 --- a/.github/workflows/default.yml +++ b/.github/workflows/default.yml @@ -148,7 +148,7 @@ jobs: - run: mkdir dist && touch dist/empty - name: Lint - uses: golangci/golangci-lint-action@v9 + uses: golangci/golangci-lint-action@1e7e51e771db61008b38414a730f564565cf7c20 # v9 with: version: latest args: --timeout 5m diff --git a/.github/workflows/documentation.yml b/.github/workflows/documentation.yml index 1df5d9df3..85ab05d85 100644 --- a/.github/workflows/documentation.yml +++ b/.github/workflows/documentation.yml @@ -29,7 +29,7 @@ jobs: run: make install docs - name: Deploy to docs repo - uses: peaceiris/actions-gh-pages@v4 + uses: peaceiris/actions-gh-pages@4f9cc6602d3f66b9c108549d475ec49e8ef4d45e # v4 with: personal_token: ${{ secrets.DOCS_DEPLOY_TOKEN }} publish_dir: ./templates/docs @@ -61,7 +61,7 @@ jobs: cp ./server/openapi.yaml ./openapi-deploy/openapi.yaml - name: Deploy OpenAPI spec to docs repo - uses: peaceiris/actions-gh-pages@v4 + uses: peaceiris/actions-gh-pages@4f9cc6602d3f66b9c108549d475ec49e8ef4d45e # v4 with: personal_token: ${{ secrets.DOCS_DEPLOY_TOKEN }} publish_dir: ./openapi-deploy diff --git a/.github/workflows/nightly.yml b/.github/workflows/nightly.yml index a1eb79152..6bb48dce4 100644 --- a/.github/workflows/nightly.yml +++ b/.github/workflows/nightly.yml @@ -66,17 +66,17 @@ jobs: key: ${{ runner.os }}-${{ github.sha }}-dist - name: Login - uses: docker/login-action@v4 + uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4 with: username: ${{ secrets.DOCKER_USER }} password: ${{ secrets.DOCKER_PASS }} - name: Setup Buildx - uses: docker/setup-buildx-action@v4 + uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4 - name: Define tags id: meta - uses: docker/metadata-action@v6 + uses: docker/metadata-action@030e881283bb7a6894de51c315a6bfe6a94e05cf # v6 with: images: evcc/evcc tags: | @@ -84,7 +84,7 @@ jobs: type=raw,value=nightly.{{date 'YYYYMMDD'}}-{{sha}} - name: Publish - uses: docker/build-push-action@v7 + uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v7 with: context: . platforms: linux/amd64,linux/arm64,linux/arm/v6 @@ -175,7 +175,7 @@ jobs: key: ${{ runner.os }}-${{ github.sha }}-dist - name: Create nightly build - uses: goreleaser/goreleaser-action@v7 + uses: goreleaser/goreleaser-action@1a80836c5c9d9e5755a25cb59ec6f45a3b5f41a8 # v7 with: version: '~> v2' args: --snapshot -f .goreleaser-nightly.yml --clean @@ -187,7 +187,7 @@ jobs: python-version: 3.12 - name: Install Cloudsmith CLI - run: pip install --upgrade cloudsmith-cli + run: pip install cloudsmith-cli==1.16.0 - name: Publish .deb to Cloudsmith env: diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index ff0642ad8..e95222f6a 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -31,23 +31,23 @@ jobs: persist-credentials: false - name: Login - uses: docker/login-action@v4 + uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4 with: username: ${{ secrets.DOCKER_USER }} password: ${{ secrets.DOCKER_PASS }} - name: Setup Buildx - uses: docker/setup-buildx-action@v4 + uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4 - name: Meta id: meta - uses: docker/metadata-action@v6 + uses: docker/metadata-action@030e881283bb7a6894de51c315a6bfe6a94e05cf # v6 with: images: | evcc/evcc - name: Publish - uses: docker/build-push-action@v7 + uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v7 with: context: . platforms: linux/amd64,linux/arm64,linux/arm/v6 @@ -103,7 +103,7 @@ jobs: # run: make image-rootfs - name: Create Github Release - uses: goreleaser/goreleaser-action@v7 + uses: goreleaser/goreleaser-action@1a80836c5c9d9e5755a25cb59ec6f45a3b5f41a8 # v7 with: version: '~> v2' args: release --clean @@ -116,7 +116,7 @@ jobs: python-version: 3.12 - name: Install Cloudsmith CLI - run: pip install --upgrade cloudsmith-cli + run: pip install cloudsmith-cli==1.16.0 - name: Publish .deb to Cloudsmith env: @@ -138,7 +138,7 @@ jobs: - uses: actions/checkout@v6 with: persist-credentials: false - - uses: superfly/flyctl-actions/setup-flyctl@master + - uses: superfly/flyctl-actions/setup-flyctl@ed8efb33836e8b2096c7fd3ba1c8afe303ebbff1 # master - run: flyctl deploy --local-only --config packaging/fly.toml hassio: @@ -152,7 +152,7 @@ jobs: steps: - name: Checkout - uses: actions/checkout@master + uses: actions/checkout@v6 with: repository: evcc-io/hassio-addon token: ${{ secrets.HASSIO_DEPLOY_TOKEN }} diff --git a/.github/workflows/schema.yml b/.github/workflows/schema.yml index 4b11c97f3..4fbf3dd55 100644 --- a/.github/workflows/schema.yml +++ b/.github/workflows/schema.yml @@ -21,7 +21,7 @@ jobs: - uses: actions/checkout@v6 with: persist-credentials: false - - uses: nwisbeta/validate-yaml-schema@v2.0.0 + - uses: nwisbeta/validate-yaml-schema@c3734e647d2a3beb98b9132330067e900fdbd1a2 # v2.0.0 with: yamlSchemasJson: | { diff --git a/.github/workflows/website.yml b/.github/workflows/website.yml index 6074e416e..7978354d3 100644 --- a/.github/workflows/website.yml +++ b/.github/workflows/website.yml @@ -32,7 +32,7 @@ jobs: run: rm templates/evcc.io/.gitignore - name: Deploy to evcc.io repo - uses: peaceiris/actions-gh-pages@v4 + uses: peaceiris/actions-gh-pages@4f9cc6602d3f66b9c108549d475ec49e8ef4d45e # v4 with: personal_token: ${{ secrets.WEBSITE_DEPLOY_TOKEN }} publish_dir: ./templates/evcc.io/ diff --git a/Dockerfile b/Dockerfile index 828b603e7..6c7771a4f 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,5 +1,5 @@ # STEP 1 build ui -FROM --platform=$BUILDPLATFORM node:24-alpine AS node +FROM --platform=$BUILDPLATFORM node:24-alpine@sha256:d1b3b4da11eefd5941e7f0b9cf17783fc99d9c6fc34884a665f40a06dbdfc94f AS node RUN apk update && apk add --no-cache make @@ -21,7 +21,7 @@ RUN make ui # STEP 2 build executable binary -FROM --platform=$BUILDPLATFORM golang:1.26-alpine AS builder +FROM --platform=$BUILDPLATFORM golang:1.26-alpine@sha256:f85330846cde1e57ca9ec309382da3b8e6ae3ab943d2739500e08c86393a21b1 AS builder # Install git + SSL ca certificates. # Git is required for fetching the dependencies. @@ -68,7 +68,7 @@ RUN --mount=type=cache,target=${GOCACHE} --mount=type=cache,target=${GOMODCACHE} # STEP 3 build a small image including module support -FROM alpine:3.22 +FROM alpine:3.22@sha256:310c62b5e7ca5b08167e4384c68db0fd2905dd9c7493756d356e893909057601 WORKDIR /app