Backport of SEC-090: Automated trusted workflow pinning (2024-06-03) into release/0.16.x #4862
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Backport
This PR is auto-generated from #4858 to be assessed for backporting due to the inclusion of the label backport/0.16.x.
WARNING automatic cherry-pick of commits failed. Commits will require human attention.
The below text is copied from the body of the original PR.
Bumping GitHub Actions version to latest TSCCR release.
.github/workflows/actionlint.yml
actions/checkout
fromv4.1.4
tov4.1.6
(release notes).github/workflows/build.yml
actions/checkout
fromv4.1.4
tov4.1.6
(release notes)actions/checkout
fromv4.1.4
tov4.1.6
(release notes)actions/setup-go
fromv5.0.0
tov5.0.1
(release notes)actions/checkout
fromv4.1.4
tov4.1.6
(release notes)actions/checkout
fromv4.1.4
tov4.1.6
(release notes)actions/checkout
fromv4.1.4
tov4.1.6
(release notes)actions/setup-go
fromv5.0.0
tov5.0.1
(release notes)actions/checkout
fromv4.1.4
tov4.1.6
(release notes)actions/setup-go
fromv5.0.0
tov5.0.1
(release notes)actions/checkout
fromv4.1.4
tov4.1.6
(release notes)actions/setup-go
fromv5.0.0
tov5.0.1
(release notes)actions/checkout
fromv4.1.4
tov4.1.6
(release notes).github/workflows/enos-fmt.yml
actions/checkout
fromv4.1.4
tov4.1.6
(release notes).github/workflows/enos-run.yml
actions/checkout
fromv4.1.4
tov4.1.6
(release notes)actions/setup-go
fromv5.0.0
tov5.0.1
(release notes)actions/checkout
fromv4.1.4
tov4.1.6
(release notes)actions/setup-go
fromv5.0.0
tov5.0.1
(release notes)actions/checkout
fromv4.1.4
tov4.1.6
(release notes).github/workflows/fuzz.yml
actions/checkout
fromv4.1.4
tov4.1.6
(release notes)actions/setup-go
fromv5.0.0
tov5.0.1
(release notes).github/workflows/linting.yml
actions/checkout
fromv4.1.4
tov4.1.6
(release notes)actions/setup-go
fromv5.0.0
tov5.0.1
(release notes).github/workflows/make-gen-delta.yml
actions/checkout
fromv4.1.4
tov4.1.6
(release notes)actions/setup-go
fromv5.0.0
tov5.0.1
(release notes).github/workflows/schema-diff.yml
actions/checkout
fromv4.1.4
tov4.1.6
(release notes).github/workflows/security-scan.yml
actions/checkout
fromv4.1.4
tov4.1.6
(release notes)actions/setup-go
fromv5.0.0
tov5.0.1
(release notes)actions/checkout
fromv4.1.4
tov4.1.6
(release notes)github/codeql-action/upload-sarif
fromcodeql-bundle-v2.17.1
tocodeql-bundle-v2.17.3
(release notes).github/workflows/test-ci-bootstrap-oss.yml
actions/checkout
fromv4.1.4
tov4.1.6
(release notes).github/workflows/test-ci-cleanup-oss.yml
actions/checkout
fromv4.1.4
tov4.1.6
(release notes).github/workflows/test-cli-ui_oss.yml
actions/checkout
fromv4.1.4
tov4.1.6
(release notes).github/workflows/test-race.yml
actions/checkout
fromv4.1.4
tov4.1.6
(release notes)actions/setup-go
fromv5.0.0
tov5.0.1
(release notes)actions/checkout
fromv4.1.4
tov4.1.6
(release notes)actions/setup-go
fromv5.0.0
tov5.0.1
(release notes)actions/checkout
fromv4.1.4
tov4.1.6
(release notes)actions/setup-go
fromv5.0.0
tov5.0.1
(release notes).github/workflows/test-sql.yml
actions/checkout
fromv4.1.4
tov4.1.6
(release notes).github/workflows/test.yml
actions/checkout
fromv4.1.4
tov4.1.6
(release notes)actions/setup-go
fromv5.0.0
tov5.0.1
(release notes)actions/checkout
fromv4.1.4
tov4.1.6
(release notes)actions/setup-go
fromv5.0.0
tov5.0.1
(release notes)actions/checkout
fromv4.1.4
tov4.1.6
(release notes)actions/setup-go
fromv5.0.0
tov5.0.1
(release notes).github/workflows/trigger-merge-to-downstream.yml
actions/checkout
fromv4.1.4
tov4.1.6
(release notes)This PR was auto-generated by security-tsccr/actions/runs/9328086659
You can alter the configuration of this automation via the hcl config in security-tsccr/automation
This PR can be regenerated by dispatching the GitHub workflow Pin Action Refs. Please reach out to #team-prodsec if you have any questions.