From e1f16e71ebf7c5e01b77d0ee5b7abbb6b7f2e3f0 Mon Sep 17 00:00:00 2001 From: Mahangu Weerasinghe Date: Mon, 8 Jun 2026 10:54:53 +0530 Subject: [PATCH] chore: pin third-party GitHub Actions to commit SHAs Tracking: DEVPROD-1072 --- .github/dependabot.yml | 22 ++++++++++++++++++++++ .github/workflows/php-coding-standards.yml | 2 +- .github/workflows/php-syntax-errors.yml | 2 +- .github/workflows/phpunit-tests.yml | 2 +- 4 files changed, 25 insertions(+), 3 deletions(-) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..7ddd384 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,22 @@ +version: 2 +updates: + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "weekly" + day: "monday" + open-pull-requests-limit: 10 + groups: + actions-minor-patch: + patterns: + - "*" + update-types: + - "minor" + - "patch" + actions-major: + patterns: + - "*" + update-types: + - "major" + cooldown: + default-days: 7 diff --git a/.github/workflows/php-coding-standards.yml b/.github/workflows/php-coding-standards.yml index f28dccd..d94a313 100644 --- a/.github/workflows/php-coding-standards.yml +++ b/.github/workflows/php-coding-standards.yml @@ -18,7 +18,7 @@ jobs: - uses: actions/checkout@v4 - name: Setup proper PHP version - uses: shivammathur/setup-php@v2 + uses: shivammathur/setup-php@7c071dfe9dc99bdf297fa79cb49ea005b9fcadbc # 2.37.1 with: php-version: ${{ matrix.php }} tools: composer diff --git a/.github/workflows/php-syntax-errors.yml b/.github/workflows/php-syntax-errors.yml index 506aceb..ecf8274 100644 --- a/.github/workflows/php-syntax-errors.yml +++ b/.github/workflows/php-syntax-errors.yml @@ -18,7 +18,7 @@ jobs: - uses: actions/checkout@v4 - name: Setup proper PHP version - uses: shivammathur/setup-php@v2 + uses: shivammathur/setup-php@7c071dfe9dc99bdf297fa79cb49ea005b9fcadbc # 2.37.1 with: php-version: ${{ matrix.php }} diff --git a/.github/workflows/phpunit-tests.yml b/.github/workflows/phpunit-tests.yml index 51e59f4..38d741b 100644 --- a/.github/workflows/phpunit-tests.yml +++ b/.github/workflows/phpunit-tests.yml @@ -30,7 +30,7 @@ jobs: - uses: actions/checkout@v4 - name: Setup PHP - uses: shivammathur/setup-php@v2 + uses: shivammathur/setup-php@7c071dfe9dc99bdf297fa79cb49ea005b9fcadbc # 2.37.1 with: php-version: 8.2 tools: composer