diff --git a/.github/workflows/_ci.yml b/.github/workflows/_ci.yml index bcc15b6..3ef37e4 100644 --- a/.github/workflows/_ci.yml +++ b/.github/workflows/_ci.yml @@ -21,7 +21,7 @@ jobs: - name: "Check out repository code" uses: "actions/checkout@v7" - name: "Set up Python" - uses: "actions/setup-python@v6" + uses: "actions/setup-python@v7" with: python-version: "3.12" - name: "Install yamllint" diff --git a/.github/workflows/ntc-ci.yml b/.github/workflows/ntc-ci.yml index 4826e2a..4b242b6 100644 --- a/.github/workflows/ntc-ci.yml +++ b/.github/workflows/ntc-ci.yml @@ -252,7 +252,7 @@ jobs: if: "needs.config.outputs.regenerate_lockfile == 'true'" run: "poetry lock --regenerate" - name: "Upload poetry.lock" - uses: "actions/upload-artifact@v4" + uses: "actions/upload-artifact@v7" with: name: "poetry-lock" path: "poetry.lock" @@ -273,7 +273,7 @@ jobs: - name: "Check out repository code" uses: "actions/checkout@v7" - name: "Download poetry.lock artifact" - uses: "actions/download-artifact@v4" + uses: "actions/download-artifact@v8" with: name: "poetry-lock" - name: "Setup environment" @@ -297,7 +297,7 @@ jobs: - name: "Check out repository code" uses: "actions/checkout@v7" - name: "Download poetry.lock artifact" - uses: "actions/download-artifact@v4" + uses: "actions/download-artifact@v8" with: name: "poetry-lock" - name: "Setup environment" @@ -372,9 +372,9 @@ jobs: poetry run invoke lock --constrain-nautobot-ver --constrain-python-ver="$PYTHON_VERSION" - name: "Set up Docker Buildx" id: "buildx" - uses: "docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e" # v4.3.0 + uses: "docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069" # v4.4.1 - name: "Build" - uses: "docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a" # v7.3.0 + uses: "docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc" # v7.4.0 with: builder: "${{ steps.buildx.outputs.name }}" context: "./" @@ -442,10 +442,10 @@ jobs: - name: "Set up Docker Buildx" if: "inputs.project_type == 'nautobot-app'" id: "buildx" - uses: "docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e" # v4.3.0 + uses: "docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069" # v4.4.1 - name: "Build" if: "inputs.project_type == 'nautobot-app'" - uses: "docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a" # v7.3.0 + uses: "docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc" # v7.4.0 with: builder: "${{ steps.buildx.outputs.name }}" context: "./" @@ -506,9 +506,9 @@ jobs: poetry run invoke lock --constrain-nautobot-ver --constrain-python-ver="$PYTHON_VERSION" - name: "Set up Docker Buildx" id: "buildx" - uses: "docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e" # v4.3.0 + uses: "docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069" # v4.4.1 - name: "Build" - uses: "docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a" # v7.3.0 + uses: "docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc" # v7.4.0 with: builder: "${{ steps.buildx.outputs.name }}" context: "./" @@ -532,7 +532,7 @@ jobs: - name: "Generate Coverage Comment" if: "needs.config.outputs.is_feature_pr == 'true'" id: "coverage_comment" - uses: "py-cov-action/python-coverage-comment-action@d1ff8fbb5ff80feedb3faa0f6d7b424f417ad0e1" # v3.30 + uses: "py-cov-action/python-coverage-comment-action@e5fb2218463c3377f3504b0c5b5646ed53da7a2f" # v4.5 with: GITHUB_TOKEN: "${{ secrets.GITHUB_TOKEN }}" MINIMUM_GREEN: "${{ inputs.coverage_minimum_green }}" @@ -541,7 +541,7 @@ jobs: ANNOTATION_TYPE: "warning" - name: "Store Pull Request comment to be posted" if: "needs.config.outputs.is_feature_pr == 'true'" - uses: "actions/upload-artifact@v4" + uses: "actions/upload-artifact@v7" with: name: "python-coverage-comment-action" path: "python-coverage-comment-action.txt" @@ -559,7 +559,7 @@ jobs: with: fetch-depth: "0" - name: "Download poetry.lock artifact" - uses: "actions/download-artifact@v4" + uses: "actions/download-artifact@v8" with: name: "poetry-lock" - name: "Setup environment" diff --git a/.github/workflows/ntc-coverage.yml b/.github/workflows/ntc-coverage.yml index 1120ccd..21de0f9 100644 --- a/.github/workflows/ntc-coverage.yml +++ b/.github/workflows/ntc-coverage.yml @@ -36,7 +36,7 @@ jobs: # DO NOT run actions/checkout here, for security reasons. # See https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ - name: "Post comment" - uses: "py-cov-action/python-coverage-comment-action@d1ff8fbb5ff80feedb3faa0f6d7b424f417ad0e1" # v3.30 + uses: "py-cov-action/python-coverage-comment-action@e5fb2218463c3377f3504b0c5b5646ed53da7a2f" # v4.5 with: GITHUB_TOKEN: "${{ secrets.GITHUB_TOKEN }}" GITHUB_PR_RUN_ID: "${{ github.event.workflow_run.id }}" diff --git a/.github/workflows/ntc-release.yml b/.github/workflows/ntc-release.yml index 723d89a..17f6942 100644 --- a/.github/workflows/ntc-release.yml +++ b/.github/workflows/ntc-release.yml @@ -107,7 +107,7 @@ jobs: exit 1 fi - - uses: "actions/upload-artifact@v4" + - uses: "actions/upload-artifact@v7" with: name: "distfiles" path: "dist/" @@ -123,7 +123,7 @@ jobs: steps: - uses: "actions/checkout@v7" - name: "Retrieve built package from cache" - uses: "actions/download-artifact@v4" + uses: "actions/download-artifact@v8" with: name: "distfiles" path: "dist/" @@ -144,14 +144,14 @@ jobs: id-token: "write" steps: - name: "Retrieve built package from cache" - uses: "actions/download-artifact@v4" + uses: "actions/download-artifact@v8" with: name: "distfiles" path: "dist/" - name: "Publish package distributions to PyPI" if: "inputs.publish_target == 'pypi'" - uses: "pypa/gh-action-pypi-publish@ed0c53931b1dc9bd32cbe73a98c7f6766f8a527e" # v1.13.0 + uses: "pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33" # v1.14.2 - name: "Check out repository code" if: "inputs.publish_target == 'artifactory'" @@ -190,7 +190,7 @@ jobs: steps: - name: "Send a notification to Slack" if: "${{ env.SLACK_WEBHOOK_URL != '' }}" - uses: "slackapi/slack-github-action@fcfb566f8b0aab22203f066d80ca1d7e4b5d05b3" # v1.27.1 + uses: "slackapi/slack-github-action@dcb1066f776dd043e64d0e8ba94ca15cc7e1875d" # v4.0.0 with: payload: | {