From b582af3747adde461c119c1f022fadd6158da023 Mon Sep 17 00:00:00 2001 From: slawomirbabicz <111378977+slawomirbabicz@users.noreply.github.com> Date: Fri, 10 Apr 2026 10:51:28 +0200 Subject: [PATCH 1/8] chore: pin actions to SHA in .github/workflows/audit.yml --- .github/workflows/audit.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/audit.yml b/.github/workflows/audit.yml index 2f72ebc..92c32c6 100644 --- a/.github/workflows/audit.yml +++ b/.github/workflows/audit.yml @@ -13,7 +13,7 @@ jobs: uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 - name: Setup PNPM - uses: dfinity/ci-tools/actions/setup-pnpm@main + uses: dfinity/ci-tools/actions/setup-pnpm@afeee4fbdc0683a88ec5a74ed7f59a2ce0e833ad # main - name: Audit run: pnpm audit From bf95ddee4c8ae38028601addfaf09b87536b5070 Mon Sep 17 00:00:00 2001 From: slawomirbabicz <111378977+slawomirbabicz@users.noreply.github.com> Date: Fri, 10 Apr 2026 10:51:29 +0200 Subject: [PATCH 2/8] chore: pin actions to SHA in .github/workflows/codestyle.yml --- .github/workflows/codestyle.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/codestyle.yml b/.github/workflows/codestyle.yml index d3c20cd..1c935df 100644 --- a/.github/workflows/codestyle.yml +++ b/.github/workflows/codestyle.yml @@ -13,7 +13,7 @@ jobs: uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 - name: Setup PNPM - uses: dfinity/ci-tools/actions/setup-pnpm@main + uses: dfinity/ci-tools/actions/setup-pnpm@afeee4fbdc0683a88ec5a74ed7f59a2ce0e833ad # main - name: Check JS Codestyle run: pnpm codestyle:check From b0afde134b1ff04b73cb889a183c4e05a6eee71f Mon Sep 17 00:00:00 2001 From: slawomirbabicz <111378977+slawomirbabicz@users.noreply.github.com> Date: Fri, 10 Apr 2026 10:51:31 +0200 Subject: [PATCH 3/8] chore: pin actions to SHA in .github/workflows/commitizen.yml --- .github/workflows/commitizen.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/commitizen.yml b/.github/workflows/commitizen.yml index 106b920..18bfb96 100644 --- a/.github/workflows/commitizen.yml +++ b/.github/workflows/commitizen.yml @@ -8,12 +8,12 @@ jobs: check_pr_title: name: check_pr_title if: github.event_name == 'pull_request' - uses: dfinity/ci-tools/.github/workflows/check-pr-title.yaml@main + uses: dfinity/ci-tools/.github/workflows/check-pr-title.yaml@afeee4fbdc0683a88ec5a74ed7f59a2ce0e833ad # main check_commit_messages: name: check_commit_messages if: github.event_name == 'merge_group' - uses: dfinity/ci-tools/.github/workflows/check-commit-messages.yaml@main + uses: dfinity/ci-tools/.github/workflows/check-commit-messages.yaml@afeee4fbdc0683a88ec5a74ed7f59a2ce0e833ad # main commitizen: name: commitizen:required From bdec2bbe0d56b43d9b88bd8dee872fa44580d2ad Mon Sep 17 00:00:00 2001 From: slawomirbabicz <111378977+slawomirbabicz@users.noreply.github.com> Date: Fri, 10 Apr 2026 10:51:32 +0200 Subject: [PATCH 4/8] chore: pin actions to SHA in .github/workflows/create-release-pr.yml --- .github/workflows/create-release-pr.yml | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/.github/workflows/create-release-pr.yml b/.github/workflows/create-release-pr.yml index 821df65..84b4ee5 100644 --- a/.github/workflows/create-release-pr.yml +++ b/.github/workflows/create-release-pr.yml @@ -30,20 +30,20 @@ jobs: fetch-depth: 0 - name: Setup Python - uses: dfinity/ci-tools/actions/setup-python@main + uses: dfinity/ci-tools/actions/setup-python@afeee4fbdc0683a88ec5a74ed7f59a2ce0e833ad # main - name: Setup Commitizen - uses: dfinity/ci-tools/actions/setup-commitizen@main + uses: dfinity/ci-tools/actions/setup-commitizen@afeee4fbdc0683a88ec5a74ed7f59a2ce0e833ad # main - name: Setup PNPM - uses: dfinity/ci-tools/actions/setup-pnpm@main + uses: dfinity/ci-tools/actions/setup-pnpm@afeee4fbdc0683a88ec5a74ed7f59a2ce0e833ad # main - name: Build package run: pnpm build - name: Bump version id: bump_version - uses: dfinity/ci-tools/actions/bump-version@main + uses: dfinity/ci-tools/actions/bump-version@afeee4fbdc0683a88ec5a74ed7f59a2ce0e833ad # main with: prerelease: ${{ inputs.beta_release == true && 'beta' || '' }} @@ -51,7 +51,7 @@ jobs: run: echo "Bumping to version ${{ steps.bump_version.outputs.version }}" - name: Create Pull Request - uses: dfinity/ci-tools/actions/create-pr@main + uses: dfinity/ci-tools/actions/create-pr@afeee4fbdc0683a88ec5a74ed7f59a2ce0e833ad # main with: token: ${{ steps.generate_token.outputs.token }} branch_name: 'release/${{ steps.bump_version.outputs.version }}' From 17a5e43420c71a1e9c9013f3e3521d2cc6d937f5 Mon Sep 17 00:00:00 2001 From: slawomirbabicz <111378977+slawomirbabicz@users.noreply.github.com> Date: Fri, 10 Apr 2026 10:51:34 +0200 Subject: [PATCH 5/8] chore: pin actions to SHA in .github/workflows/generate-changelog.yml --- .github/workflows/generate-changelog.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/generate-changelog.yml b/.github/workflows/generate-changelog.yml index 61608be..107b900 100644 --- a/.github/workflows/generate-changelog.yml +++ b/.github/workflows/generate-changelog.yml @@ -7,7 +7,7 @@ on: jobs: generate_changelog: - uses: dfinity/ci-tools/.github/workflows/generate-changelog.yaml@main + uses: dfinity/ci-tools/.github/workflows/generate-changelog.yaml@afeee4fbdc0683a88ec5a74ed7f59a2ce0e833ad # main with: token_app_id: ${{ vars.PR_AUTOMATION_BOT_PUBLIC_APP_ID }} environment: release From 2147345108582b5ccc8393ea4ceb4a5a71e43423 Mon Sep 17 00:00:00 2001 From: slawomirbabicz <111378977+slawomirbabicz@users.noreply.github.com> Date: Fri, 10 Apr 2026 10:51:35 +0200 Subject: [PATCH 6/8] chore: pin actions to SHA in .github/workflows/publish-docs.yml --- .github/workflows/publish-docs.yml | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/.github/workflows/publish-docs.yml b/.github/workflows/publish-docs.yml index 7e41ec6..9068376 100644 --- a/.github/workflows/publish-docs.yml +++ b/.github/workflows/publish-docs.yml @@ -34,15 +34,15 @@ jobs: ref: ${{ inputs.ref }} - name: Setup Python - uses: dfinity/ci-tools/actions/setup-python@main + uses: dfinity/ci-tools/actions/setup-python@afeee4fbdc0683a88ec5a74ed7f59a2ce0e833ad # main - name: Setup Commitizen - uses: dfinity/ci-tools/actions/setup-commitizen@main + uses: dfinity/ci-tools/actions/setup-commitizen@afeee4fbdc0683a88ec5a74ed7f59a2ce0e833ad # main - name: Setup PNPM - uses: dfinity/ci-tools/actions/setup-pnpm@main + uses: dfinity/ci-tools/actions/setup-pnpm@afeee4fbdc0683a88ec5a74ed7f59a2ce0e833ad # main - - uses: dfinity/ci-tools/actions/extract-version@main + - uses: dfinity/ci-tools/actions/extract-version@afeee4fbdc0683a88ec5a74ed7f59a2ce0e833ad # main id: extract-version - name: Prepare version @@ -70,7 +70,7 @@ jobs: path: icp-pages - name: Assemble docs - uses: dfinity/ci-tools/actions/assemble-docs@main + uses: dfinity/ci-tools/actions/assemble-docs@afeee4fbdc0683a88ec5a74ed7f59a2ce0e833ad # main with: assets_dir: 'docs/dist/${{ steps.ver.outputs.major_minor_version }}' version: ${{ steps.ver.outputs.major_minor_version }} @@ -79,7 +79,7 @@ jobs: version_in_title: ${{ steps.ver.outputs.major_minor_patch_version }} - name: Assemble docs - uses: dfinity/ci-tools/actions/assemble-docs@main + uses: dfinity/ci-tools/actions/assemble-docs@afeee4fbdc0683a88ec5a74ed7f59a2ce0e833ad # main with: assets_dir: 'docs/dist/latest' version: 'latest' @@ -87,7 +87,7 @@ jobs: version_label: 'Latest (${{ steps.ver.outputs.major_minor_patch_version }})' - name: Submit Documentation - uses: dfinity/ci-tools/actions/submit-docs@main + uses: dfinity/ci-tools/actions/submit-docs@afeee4fbdc0683a88ec5a74ed7f59a2ce0e833ad # main with: destination_repo: 'dfinity/icp-js-sdk-docs' token: ${{ steps.generate_token.outputs.token }} From e2f4fc4300b99aa10a015d79b9eeaa53ed6d2aa6 Mon Sep 17 00:00:00 2001 From: slawomirbabicz <111378977+slawomirbabicz@users.noreply.github.com> Date: Fri, 10 Apr 2026 10:51:37 +0200 Subject: [PATCH 7/8] chore: pin actions to SHA in .github/workflows/release.yml --- .github/workflows/release.yml | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index c2719bb..6249700 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -24,19 +24,19 @@ jobs: uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 - name: Setup Python - uses: dfinity/ci-tools/actions/setup-python@main + uses: dfinity/ci-tools/actions/setup-python@afeee4fbdc0683a88ec5a74ed7f59a2ce0e833ad # main - name: Setup Commitizen - uses: dfinity/ci-tools/actions/setup-commitizen@main + uses: dfinity/ci-tools/actions/setup-commitizen@afeee4fbdc0683a88ec5a74ed7f59a2ce0e833ad # main - name: Setup PNPM - uses: dfinity/ci-tools/actions/setup-pnpm@main + uses: dfinity/ci-tools/actions/setup-pnpm@afeee4fbdc0683a88ec5a74ed7f59a2ce0e833ad # main - name: Determine if Beta Release id: is_beta - uses: dfinity/ci-tools/actions/is-beta-tag@main + uses: dfinity/ci-tools/actions/is-beta-tag@afeee4fbdc0683a88ec5a74ed7f59a2ce0e833ad # main - - uses: dfinity/ci-tools/actions/extract-version@main + - uses: dfinity/ci-tools/actions/extract-version@afeee4fbdc0683a88ec5a74ed7f59a2ce0e833ad # main id: extract-version - name: Prepare version @@ -63,7 +63,7 @@ jobs: $release_cmd - name: Generate release notes - uses: dfinity/ci-tools/actions/generate-release-notes@main + uses: dfinity/ci-tools/actions/generate-release-notes@afeee4fbdc0683a88ec5a74ed7f59a2ce0e833ad # main - name: Create Github release uses: ncipollo/release-action@b7eabc95ff50cbeeedec83973935c8f306dfcd0b # v1.20.0 From 95d8db4c3cf491a082a8ad8911f8fbc2db466722 Mon Sep 17 00:00:00 2001 From: slawomirbabicz <111378977+slawomirbabicz@users.noreply.github.com> Date: Fri, 10 Apr 2026 10:51:38 +0200 Subject: [PATCH 8/8] chore: pin actions to SHA in .github/workflows/test.yml --- .github/workflows/test.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 00a2a29..4119ef2 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -13,7 +13,7 @@ jobs: uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 - name: Setup PNPM - uses: dfinity/ci-tools/actions/setup-pnpm@main + uses: dfinity/ci-tools/actions/setup-pnpm@afeee4fbdc0683a88ec5a74ed7f59a2ce0e833ad # main - name: JS Build run: pnpm build