From 311e4306e63b463e6ada9091eea3d36f53b02835 Mon Sep 17 00:00:00 2001 From: Hauser Date: Wed, 23 Sep 2026 19:20:39 +0800 Subject: [PATCH] chore(ci): complete action pin and HAProxy upgrades (#8090) --- .github/actions/quick-checks/action.yml | 2 +- .github/actions/setup/action.yml | 2 +- .../architecture-migration-rules.yml | 2 +- .github/workflows/audit.yml | 4 +- .github/workflows/build.yml | 14 ++-- .github/workflows/cache-warm.yml | 10 +-- .github/workflows/ci.yml | 78 +++++++++---------- .github/workflows/cla.yml | 2 +- .../connect-performance-drive-acceptance.yml | 10 +-- ...connect-performance-network-acceptance.yml | 10 +-- .../connect-profile-cpu-acceptance.yml | 10 +-- .../connect-profile-threads-acceptance.yml | 10 +-- .../workflows/connect-top-api-acceptance.yml | 10 +-- .../workflows/connect-top-disk-acceptance.yml | 6 +- .../connect-top-locks-acceptance.yml | 10 +-- .../workflows/connect-top-rpc-acceptance.yml | 10 +-- .github/workflows/coverage.yml | 4 +- .github/workflows/docker.yml | 8 +- .github/workflows/e2e-distributed.yml | 6 +- .github/workflows/e2e-replication-nightly.yml | 8 +- .github/workflows/e2e-s3tests.yml | 21 +++-- .github/workflows/e2e-upgrade.yml | 6 +- .github/workflows/functional-chain-health.yml | 2 +- .github/workflows/fuzz.yml | 20 ++--- .github/workflows/helm-package.yml | 4 +- .github/workflows/minio-interop.yml | 4 +- .github/workflows/mint.yml | 6 +- .github/workflows/nightly-gnu.yml | 16 ++-- .github/workflows/nix-flake-update.yml | 8 +- .github/workflows/nix.yml | 6 +- .github/workflows/oidc-keycloak.yml | 2 +- .../workflows/on-demand-migration-interop.yml | 10 +-- .github/workflows/package.yml | 6 +- .github/workflows/performance-ab.yml | 8 +- .github/workflows/runner-hygiene.yml | 4 +- .../rustfs-fault-tolerance-matrix.yml | 4 +- .../workflows/rustfs-fault-tolerance-test.yml | 8 +- .github/workflows/rustfs-functional-chain.yml | 8 +- .github/workflows/rustfs-heal-test.yml | 8 +- .github/workflows/rustfs-kms-test.yml | 8 +- .github/workflows/rustfs-performance-test.yml | 10 +-- .github/workflows/rustfs-pool-expand-test.yml | 8 +- .github/workflows/rustfs-replication-test.yml | 8 +- .github/workflows/rustfs-s3-compat-test.yml | 8 +- .github/workflows/rustfs-security-test.yml | 8 +- .github/workflows/rustfs-storage-test.yml | 8 +- .github/workflows/rustfs-table-test.yml | 8 +- .github/workflows/rustfs-tier-test.yml | 8 +- .github/workflows/rustfs-upgrade-test.yml | 8 +- .../scheduled-validation-freshness.yml | 2 +- .../scheduled-validation-watchdog.yml | 2 +- .github/workflows/stale.yml | 2 +- .github/workflows/targets-integration.yml | 6 +- scripts/check_test_wiring.py | 61 ++++++++++++--- 54 files changed, 282 insertions(+), 240 deletions(-) diff --git a/.github/actions/quick-checks/action.yml b/.github/actions/quick-checks/action.yml index e24890fb8..ca761f71f 100644 --- a/.github/actions/quick-checks/action.yml +++ b/.github/actions/quick-checks/action.yml @@ -19,7 +19,7 @@ runs: using: composite steps: - name: Install quality tools - uses: taiki-e/install-action@bffeee26d4db9be238a4ea78d8826604ebcb594d # v2 + uses: taiki-e/install-action@7623a79cdfecb99d681017af368ca353d9f49bb5 # v2 with: tool: | ripgrep@15.2.0 diff --git a/.github/actions/setup/action.yml b/.github/actions/setup/action.yml index 0dbd23da5..712afb3d0 100644 --- a/.github/actions/setup/action.yml +++ b/.github/actions/setup/action.yml @@ -109,7 +109,7 @@ runs: uses: taiki-e/install-action@96c7780c1d8a2b8723e12031def873a434d39d8d # nextest - name: Setup Rust cache - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 + uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2 with: # false is rust-cache's own default. With true, cleanup.ts returns # *before* pruning ~/.cargo/registry/src, and config.ts archives the diff --git a/.github/workflows/architecture-migration-rules.yml b/.github/workflows/architecture-migration-rules.yml index f40042a01..37d1969b0 100644 --- a/.github/workflows/architecture-migration-rules.yml +++ b/.github/workflows/architecture-migration-rules.yml @@ -53,7 +53,7 @@ jobs: persist-credentials: false - name: Install ripgrep - uses: taiki-e/install-action@bffeee26d4db9be238a4ea78d8826604ebcb594d # v2 + uses: taiki-e/install-action@7623a79cdfecb99d681017af368ca353d9f49bb5 # v2 with: tool: ripgrep@15.2.0 diff --git a/.github/workflows/audit.yml b/.github/workflows/audit.yml index 86393483d..baa256962 100644 --- a/.github/workflows/audit.yml +++ b/.github/workflows/audit.yml @@ -112,7 +112,7 @@ jobs: # default is now "false", but state it explicitly — see # scripts/security/check_cache_save_if.sh. - name: Setup Rust cache - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 + uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2 with: # Same reasoning as the setup composite: true archives every # dependency's unpacked source tree. @@ -122,7 +122,7 @@ jobs: save-if: ${{ github.ref == 'refs/heads/main' }} - name: Install cargo-deny - uses: taiki-e/install-action@bffeee26d4db9be238a4ea78d8826604ebcb594d # v2 + uses: taiki-e/install-action@7623a79cdfecb99d681017af368ca353d9f49bb5 # v2 with: tool: cargo-deny diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index b96bd76c7..555d11167 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -98,7 +98,7 @@ jobs: is_prerelease: ${{ steps.check.outputs.is_prerelease }} steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -257,7 +257,7 @@ jobs: matrix: ${{ fromJson(needs.prepare-platform-matrix.outputs.matrix) }} steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false fetch-depth: 0 @@ -702,7 +702,7 @@ jobs: exit 1 - name: Upload to GitHub artifacts - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: ${{ steps.package.outputs.package_name }} path: "rustfs-*.zip" @@ -840,7 +840,7 @@ jobs: release_url: ${{ steps.create.outputs.release_url }} steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false fetch-depth: 0 @@ -899,12 +899,12 @@ jobs: actions: read steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Download all build artifacts - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: path: ./artifacts pattern: rustfs-* @@ -1138,7 +1138,7 @@ jobs: contents: read issues: write steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + - uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Open or update failure-tracking issue diff --git a/.github/workflows/cache-warm.yml b/.github/workflows/cache-warm.yml index 62ecc2010..ee4df652e 100644 --- a/.github/workflows/cache-warm.yml +++ b/.github/workflows/cache-warm.yml @@ -109,7 +109,7 @@ jobs: FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true" steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -141,7 +141,7 @@ jobs: - name: Upload cargo timings report if: inputs.emit_timings - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: cargo-timings-ci-dev path: target/cargo-timings/ @@ -199,7 +199,7 @@ jobs: FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true" steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -230,7 +230,7 @@ jobs: FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true" steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -260,7 +260,7 @@ jobs: timeout-minutes: 60 steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 78129e1b0..ad4b0ab0b 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -77,7 +77,7 @@ jobs: outputs: mode: ${{ steps.scope.outputs.mode }} steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + - uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: fetch-depth: 2 persist-credentials: false @@ -101,11 +101,11 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 10 steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + - uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Typos check with custom config file - uses: crate-ci/typos@37bb98842b0d8c4ffebdb75301a13db0267cef89 # master + uses: crate-ci/typos@512fc24f32f44ab01972217aaaf3dc86ec234d53 # v1.50.2 # Fail early with compile-free checks for every pull request. quick-checks: @@ -115,7 +115,7 @@ jobs: timeout-minutes: 10 steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -132,7 +132,7 @@ jobs: FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true" steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: # Checkout otherwise writes the token into .git/config, where a PR's # own build.rs or proc-macro could read it back out. @@ -261,7 +261,7 @@ jobs: - name: Upload test reports and diagnostics if: always() - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: junit-test-and-lint-${{ github.run_number }} path: | @@ -305,7 +305,7 @@ jobs: FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true" steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -344,7 +344,7 @@ jobs: FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true" steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -391,7 +391,7 @@ jobs: - name: Upload ILM test diagnostics if: always() - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: ilm-integration-${{ github.run_number }}-${{ github.run_attempt }} path: | @@ -408,7 +408,7 @@ jobs: FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true" steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -449,7 +449,7 @@ jobs: FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true" steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -521,7 +521,7 @@ jobs: FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true" steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -561,7 +561,7 @@ jobs: FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true" steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -621,7 +621,7 @@ jobs: PYBUILD - name: Upload debug binary - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: rustfs-debug-binary path: | @@ -646,7 +646,7 @@ jobs: FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true" steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -662,7 +662,7 @@ jobs: run: python3 scripts/e2e_binary.py build --bins --features rio-v2,e2e-test-hooks - name: Upload debug binary - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: rustfs-debug-binary-rio-v2 path: | @@ -690,7 +690,7 @@ jobs: timeout-minutes: 30 steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -754,7 +754,7 @@ jobs: timeout-minutes: 30 steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -770,7 +770,7 @@ jobs: install-build-packaging-tools: 'false' - name: Set up Python - uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 + uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: "3.12" @@ -785,7 +785,7 @@ jobs: # Download after the cache restore so the freshly built binary from the # build job always wins over anything restored into target/debug. - name: Download debug binary - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: rustfs-debug-binary path: target/debug @@ -821,7 +821,7 @@ jobs: - name: Upload e2e smoke diagnostics if: failure() - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: e2e-smoke-diagnostics-${{ github.run_number }} path: | @@ -831,7 +831,7 @@ jobs: - name: Upload e2e smoke JUnit report if: always() - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: e2e-smoke-junit-${{ github.run_number }} path: target/nextest/e2e-smoke/junit.xml @@ -856,7 +856,7 @@ jobs: - name: Upload test logs if: failure() - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: e2e-test-logs-${{ github.run_number }} path: ${{ runner.temp }}/rustfs-e2e-*/rustfs.log @@ -879,7 +879,7 @@ jobs: timeout-minutes: 55 steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -903,7 +903,7 @@ jobs: fi - name: Set up Python - uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 + uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: "3.12" @@ -945,7 +945,7 @@ jobs: # Download after the cache restore so the freshly built binary from the # build job always wins over anything restored into target/debug. - name: Download debug binary - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: rustfs-debug-binary path: target/debug @@ -1005,7 +1005,7 @@ jobs: - name: Upload junit if: always() - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: e2e-full-junit-${{ github.run_number }} path: | @@ -1015,7 +1015,7 @@ jobs: - name: Upload startup CAS evidence if: always() - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: fresh-startup-cas-evidence-${{ github.run_number }} path: | @@ -1034,7 +1034,7 @@ jobs: timeout-minutes: 30 steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -1044,7 +1044,7 @@ jobs: rm -f /tmp/rustfs.log - name: Download debug binary - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: rustfs-debug-binary-rio-v2 path: target/debug @@ -1077,7 +1077,7 @@ jobs: - name: Upload test logs if: failure() - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: e2e-test-logs-rio-v2-${{ github.run_number }} path: /tmp/rustfs.log @@ -1090,12 +1090,12 @@ jobs: timeout-minutes: 60 steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Download debug binary - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: rustfs-debug-binary path: target/debug @@ -1120,7 +1120,7 @@ jobs: - name: Upload s3 test artifacts if: always() - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: s3tests-implemented-${{ github.run_number }} path: artifacts/s3tests-single/** @@ -1164,12 +1164,12 @@ jobs: timeout-minutes: 30 steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Download debug binary - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: rustfs-debug-binary path: target/debug @@ -1202,7 +1202,7 @@ jobs: - name: Upload s3 test artifacts if: always() - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: s3tests-lifecycle-behavior-${{ github.run_number }} path: artifacts/s3tests-single/** @@ -1233,7 +1233,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 10 steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + - uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Require the expected result of every CI lane @@ -1272,7 +1272,7 @@ jobs: contents: read issues: write steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + - uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Open or update failure-tracking issue diff --git a/.github/workflows/cla.yml b/.github/workflows/cla.yml index f2bad5b46..12ca8a533 100644 --- a/.github/workflows/cla.yml +++ b/.github/workflows/cla.yml @@ -66,7 +66,7 @@ jobs: steps: - name: Report CLA result for merge queue if: github.event_name == 'merge_group' - uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8 + uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: script: | await github.rest.checks.create({ diff --git a/.github/workflows/connect-performance-drive-acceptance.yml b/.github/workflows/connect-performance-drive-acceptance.yml index 0e9b1e049..7b96ef7d8 100644 --- a/.github/workflows/connect-performance-drive-acceptance.yml +++ b/.github/workflows/connect-performance-drive-acceptance.yml @@ -53,19 +53,19 @@ jobs: timeout-minutes: 45 steps: - name: Checkout acceptance harness - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Checkout exact RustFS source - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: path: rustfs-source persist-credentials: false ref: ${{ inputs.source_sha }} - name: Checkout exact Connect harness - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: repository: rustfs/connect path: connect-harness @@ -122,7 +122,7 @@ jobs: [[ $(jq -r '.expired' <<<"$artifact") == false ]] - name: Download exact build artifact - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: artifact-ids: ${{ inputs.artifact_id }} path: artifact @@ -183,7 +183,7 @@ jobs: - name: Upload acceptance evidence if: ${{ always() && hashFiles('performance-drive-service-job-evidence.json') != '' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: connect-performance-drive-evidence-${{ github.run_id }} path: | diff --git a/.github/workflows/connect-performance-network-acceptance.yml b/.github/workflows/connect-performance-network-acceptance.yml index 0e660b5f0..5d8b561d6 100644 --- a/.github/workflows/connect-performance-network-acceptance.yml +++ b/.github/workflows/connect-performance-network-acceptance.yml @@ -53,19 +53,19 @@ jobs: timeout-minutes: 45 steps: - name: Checkout acceptance harness - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Checkout exact RustFS source - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: path: rustfs-source persist-credentials: false ref: ${{ inputs.source_sha }} - name: Checkout exact Connect harness - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: repository: rustfs/connect path: connect-harness @@ -122,7 +122,7 @@ jobs: [[ $(jq -r '.expired' <<<"$artifact") == false ]] - name: Download exact build artifact - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: artifact-ids: ${{ inputs.artifact_id }} path: artifact @@ -183,7 +183,7 @@ jobs: - name: Upload acceptance evidence if: ${{ always() && hashFiles('performance-network-service-job-evidence.json') != '' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: connect-performance-network-evidence-${{ github.run_id }} path: | diff --git a/.github/workflows/connect-profile-cpu-acceptance.yml b/.github/workflows/connect-profile-cpu-acceptance.yml index 3c3889b2a..93b2dfe61 100644 --- a/.github/workflows/connect-profile-cpu-acceptance.yml +++ b/.github/workflows/connect-profile-cpu-acceptance.yml @@ -53,19 +53,19 @@ jobs: timeout-minutes: 45 steps: - name: Checkout acceptance harness - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Checkout exact RustFS source - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: path: rustfs-source persist-credentials: false ref: ${{ inputs.source_sha }} - name: Checkout exact Connect harness - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: repository: rustfs/connect path: connect-harness @@ -122,7 +122,7 @@ jobs: [[ $(jq -r '.expired' <<<"$artifact") == false ]] - name: Download exact build artifact - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: artifact-ids: ${{ inputs.artifact_id }} path: artifact @@ -183,7 +183,7 @@ jobs: - name: Upload acceptance evidence if: ${{ always() && hashFiles('profile-service-job-evidence.json') != '' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: connect-profile-cpu-evidence-${{ github.run_id }} path: | diff --git a/.github/workflows/connect-profile-threads-acceptance.yml b/.github/workflows/connect-profile-threads-acceptance.yml index 966509b33..a028a1e81 100644 --- a/.github/workflows/connect-profile-threads-acceptance.yml +++ b/.github/workflows/connect-profile-threads-acceptance.yml @@ -53,19 +53,19 @@ jobs: timeout-minutes: 45 steps: - name: Checkout acceptance harness - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Checkout exact RustFS source - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: path: rustfs-source persist-credentials: false ref: ${{ inputs.source_sha }} - name: Checkout exact Connect harness - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: repository: rustfs/connect path: connect-harness @@ -122,7 +122,7 @@ jobs: [[ $(jq -r '.expired' <<<"$artifact") == false ]] - name: Download exact build artifact - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: artifact-ids: ${{ inputs.artifact_id }} path: artifact @@ -183,7 +183,7 @@ jobs: - name: Upload acceptance evidence if: ${{ always() && hashFiles('profile-threads-service-job-evidence.json') != '' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: connect-profile-threads-evidence-${{ github.run_id }} path: | diff --git a/.github/workflows/connect-top-api-acceptance.yml b/.github/workflows/connect-top-api-acceptance.yml index 4ec9bb8fa..2d9e277f7 100644 --- a/.github/workflows/connect-top-api-acceptance.yml +++ b/.github/workflows/connect-top-api-acceptance.yml @@ -53,19 +53,19 @@ jobs: timeout-minutes: 45 steps: - name: Checkout acceptance harness - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Checkout exact RustFS source - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: path: rustfs-source persist-credentials: false ref: ${{ inputs.source_sha }} - name: Checkout exact Connect harness - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: repository: rustfs/connect path: connect-harness @@ -122,7 +122,7 @@ jobs: [[ $(jq -r '.expired' <<<"$artifact") == false ]] - name: Download exact build artifact - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: artifact-ids: ${{ inputs.artifact_id }} path: artifact @@ -183,7 +183,7 @@ jobs: - name: Upload acceptance evidence if: ${{ always() && hashFiles('top-api-service-job-evidence.json') != '' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: connect-top-api-evidence-${{ github.run_id }} path: | diff --git a/.github/workflows/connect-top-disk-acceptance.yml b/.github/workflows/connect-top-disk-acceptance.yml index 34a7a1ad2..e0730a342 100644 --- a/.github/workflows/connect-top-disk-acceptance.yml +++ b/.github/workflows/connect-top-disk-acceptance.yml @@ -49,7 +49,7 @@ jobs: timeout-minutes: 15 steps: - name: Checkout acceptance harness - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -83,7 +83,7 @@ jobs: [[ $(jq -r '.expired' <<<"$artifact") == false ]] - name: Download exact build artifact - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: artifact-ids: ${{ inputs.artifact_id }} path: artifact @@ -132,7 +132,7 @@ jobs: mv top-disk-runtime-evidence.bound.json top-disk-runtime-evidence.json - name: Upload acceptance evidence - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: connect-top-disk-evidence-${{ github.run_id }} path: | diff --git a/.github/workflows/connect-top-locks-acceptance.yml b/.github/workflows/connect-top-locks-acceptance.yml index ff3e34911..0c5fc317e 100644 --- a/.github/workflows/connect-top-locks-acceptance.yml +++ b/.github/workflows/connect-top-locks-acceptance.yml @@ -53,19 +53,19 @@ jobs: timeout-minutes: 45 steps: - name: Checkout acceptance harness - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Checkout exact RustFS source - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: path: rustfs-source persist-credentials: false ref: ${{ inputs.source_sha }} - name: Checkout exact Connect harness - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: repository: rustfs/connect path: connect-harness @@ -122,7 +122,7 @@ jobs: [[ $(jq -r '.expired' <<<"$artifact") == false ]] - name: Download exact build artifact - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: artifact-ids: ${{ inputs.artifact_id }} path: artifact @@ -183,7 +183,7 @@ jobs: - name: Upload acceptance evidence if: ${{ always() && hashFiles('top-locks-service-job-evidence.json') != '' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: connect-top-locks-evidence-${{ github.run_id }} path: | diff --git a/.github/workflows/connect-top-rpc-acceptance.yml b/.github/workflows/connect-top-rpc-acceptance.yml index a3097ddb0..ba5887022 100644 --- a/.github/workflows/connect-top-rpc-acceptance.yml +++ b/.github/workflows/connect-top-rpc-acceptance.yml @@ -53,19 +53,19 @@ jobs: timeout-minutes: 45 steps: - name: Checkout acceptance harness - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Checkout exact RustFS source - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: path: rustfs-source persist-credentials: false ref: ${{ inputs.source_sha }} - name: Checkout exact Connect harness - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: repository: rustfs/connect path: connect-harness @@ -122,7 +122,7 @@ jobs: [[ $(jq -r '.expired' <<<"$artifact") == false ]] - name: Download exact build artifact - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: artifact-ids: ${{ inputs.artifact_id }} path: artifact @@ -183,7 +183,7 @@ jobs: - name: Upload acceptance evidence if: ${{ always() && hashFiles('top-rpc-service-job-evidence.json') != '' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: connect-top-rpc-evidence-${{ github.run_id }} path: | diff --git a/.github/workflows/coverage.yml b/.github/workflows/coverage.yml index a0d04d147..6ceefefad 100644 --- a/.github/workflows/coverage.yml +++ b/.github/workflows/coverage.yml @@ -89,7 +89,7 @@ jobs: install-build-packaging-tools: 'false' - name: Install cargo-llvm-cov - uses: taiki-e/install-action@bffeee26d4db9be238a4ea78d8826604ebcb594d # v2 + uses: taiki-e/install-action@7623a79cdfecb99d681017af368ca353d9f49bb5 # v2 with: tool: cargo-llvm-cov @@ -112,7 +112,7 @@ jobs: - name: Upload coverage artifact if: always() - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: coverage-lcov-${{ github.run_number }} path: | diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml index fb9a80481..1908933b7 100644 --- a/.github/workflows/docker.yml +++ b/.github/workflows/docker.yml @@ -96,7 +96,7 @@ jobs: source_ref: ${{ steps.check.outputs.source_ref }} steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false # For workflow_run events, checkout the specific commit that triggered the workflow @@ -352,7 +352,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false ref: ${{ needs.build-check.outputs.source_ref }} @@ -544,7 +544,7 @@ jobs: category: container-image-${{ matrix.variant }} - name: Upload container scan report - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: container-image-scan-${{ matrix.variant }} path: trivy-${{ matrix.variant }}.sarif @@ -563,7 +563,7 @@ jobs: timeout-minutes: 10 steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false ref: ${{ needs.build-check.outputs.source_ref }} diff --git a/.github/workflows/e2e-distributed.yml b/.github/workflows/e2e-distributed.yml index 8b58fca17..889d84733 100644 --- a/.github/workflows/e2e-distributed.yml +++ b/.github/workflows/e2e-distributed.yml @@ -93,7 +93,7 @@ jobs: UPGRADE_SOURCE_SHA256: 7c789386bf85278f865b8e0d359bf4edb84d5aa408cc3fa54a18c25ca74cd6e7 steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -174,7 +174,7 @@ jobs: - name: Upload distributed e2e diagnostics if: always() - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: e2e-distributed-${{ github.run_number }} path: | @@ -206,7 +206,7 @@ jobs: contents: read issues: write steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + - uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Open or update failure-tracking issue diff --git a/.github/workflows/e2e-replication-nightly.yml b/.github/workflows/e2e-replication-nightly.yml index 2896f7fd5..b2f5b33ba 100644 --- a/.github/workflows/e2e-replication-nightly.yml +++ b/.github/workflows/e2e-replication-nightly.yml @@ -77,7 +77,7 @@ jobs: # The STS dual-node test requires awscurl and fails if it is unavailable. - name: Set up Python - uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 + uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: "3.12" @@ -108,7 +108,7 @@ jobs: - name: Upload nextest junit report if: always() - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: e2e-replication-nightly-junit-${{ github.run_number }} path: | @@ -157,7 +157,7 @@ jobs: - name: Upload cluster fault diagnostics if: always() - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: e2e-cluster-nightly-${{ github.run_number }} path: | @@ -213,7 +213,7 @@ jobs: - name: Upload protocol diagnostics if: always() - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: e2e-protocol-nightly-${{ github.run_number }} path: | diff --git a/.github/workflows/e2e-s3tests.yml b/.github/workflows/e2e-s3tests.yml index 30eba6d68..6c0416815 100644 --- a/.github/workflows/e2e-s3tests.yml +++ b/.github/workflows/e2e-s3tests.yml @@ -159,7 +159,7 @@ jobs: TEST_MODE: ${{ matrix.test-mode }} S3_SHARD_INDEX: ${{ matrix.shard-index }} steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + - uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -167,7 +167,7 @@ jobs: # ship a working pip (ci-1: a bare python3 without pip is what broke the # scheduled sweep). Keeps the workflow correct across runner drift. - name: Set up Python - uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 + uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: "3.12" @@ -264,7 +264,7 @@ jobs: hostname: rustfs4 volumes: [rustfs4-data:/data] lb: - image: haproxy:2.9 + image: haproxy:3.4.4 hostname: lb networks: [rustfs-net] ports: @@ -308,6 +308,11 @@ jobs: docker compose -f compose.yml up -d + # Validate the pinned HAProxy image parses the exact config before + # the S3 compatibility sweep starts. + docker compose -f compose.yml exec -T lb \ + haproxy -c -f /usr/local/etc/haproxy/haproxy.cfg + - name: Wait for RustFS ready run: | for _ in {1..120}; do @@ -357,7 +362,7 @@ jobs: - name: Upload artifacts if: always() && env.ACT != 'true' - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: s3tests-${{ env.TEST_MODE }}-shard-${{ matrix.shard-index }} path: artifacts/** @@ -369,12 +374,12 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 20 steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + - uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Set up Python - uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 + uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: "3.12" @@ -435,7 +440,7 @@ jobs: - name: Upload canary artifacts if: always() && env.ACT != 'true' - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: s3tests-upstream-head path: artifacts/s3tests-upstream-head/** @@ -454,7 +459,7 @@ jobs: contents: read issues: write steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + - uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Open or update failure-tracking issue diff --git a/.github/workflows/e2e-upgrade.yml b/.github/workflows/e2e-upgrade.yml index 1dd84b02a..c05f0a40d 100644 --- a/.github/workflows/e2e-upgrade.yml +++ b/.github/workflows/e2e-upgrade.yml @@ -96,7 +96,7 @@ jobs: FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true" steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -137,7 +137,7 @@ jobs: - name: Upload scanner/heal G09 evidence if: always() - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: ${{ matrix.artifact }}-g09-evidence-${{ github.run_number }} path: ${{ runner.temp }}/rustfs-upgrade-g09-evidence/${{ matrix.artifact }} @@ -146,7 +146,7 @@ jobs: - name: Upload server logs if: always() - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: ${{ matrix.artifact }}-server-logs-${{ github.run_number }} path: ${{ runner.temp }}/rustfs-upgrade-logs diff --git a/.github/workflows/functional-chain-health.yml b/.github/workflows/functional-chain-health.yml index e61ced484..bc1937ebb 100644 --- a/.github/workflows/functional-chain-health.yml +++ b/.github/workflows/functional-chain-health.yml @@ -24,7 +24,7 @@ jobs: run: python3 scripts/functional_chain_health.py --source-ref "${NIGHTLY_SOURCE_REF}" --publish --output "${RUNNER_TEMP}/chain-health.json" - name: Retain health observation if: always() - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: functional-chain-health-${{ github.run_id }}-${{ github.run_attempt }} path: ${{ runner.temp }}/chain-health.json diff --git a/.github/workflows/fuzz.yml b/.github/workflows/fuzz.yml index a5956c6e8..7c73d4b81 100644 --- a/.github/workflows/fuzz.yml +++ b/.github/workflows/fuzz.yml @@ -81,7 +81,7 @@ jobs: FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true" steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -93,7 +93,7 @@ jobs: cache-save-if: ${{ github.ref == 'refs/heads/main' || github.event_name == 'schedule' }} - name: Install cargo-fuzz - uses: taiki-e/install-action@bffeee26d4db9be238a4ea78d8826604ebcb594d # v2 + uses: taiki-e/install-action@7623a79cdfecb99d681017af368ca353d9f49bb5 # v2 with: tool: cargo-fuzz @@ -113,7 +113,7 @@ jobs: done - name: Upload prebuilt fuzz binaries - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: fuzz-prebuilt-binaries-${{ github.run_number }} path: fuzz/prebuilt/${{ env.CARGO_BUILD_TARGET }}/release/ @@ -143,12 +143,12 @@ jobs: FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true" steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Download prebuilt fuzz binaries - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: fuzz-prebuilt-binaries-${{ github.run_number }} path: fuzz/prebuilt/${{ env.CARGO_BUILD_TARGET }}/release @@ -167,7 +167,7 @@ jobs: - name: Upload fuzz smoke artifacts if: always() - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: fuzz-smoke-${{ matrix.target }}-${{ github.run_number }} path: | @@ -197,12 +197,12 @@ jobs: FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true" steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Download prebuilt fuzz binaries - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: fuzz-prebuilt-binaries-${{ github.run_number }} path: fuzz/prebuilt/${{ env.CARGO_BUILD_TARGET }}/release @@ -221,7 +221,7 @@ jobs: - name: Upload nightly fuzz artifacts if: always() - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: fuzz-nightly-${{ matrix.target }}-${{ github.run_number }} path: | @@ -246,7 +246,7 @@ jobs: contents: read issues: write steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + - uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Open or update failure-tracking issue diff --git a/.github/workflows/helm-package.yml b/.github/workflows/helm-package.yml index 341c3424d..fa40dc023 100644 --- a/.github/workflows/helm-package.yml +++ b/.github/workflows/helm-package.yml @@ -107,7 +107,7 @@ jobs: --version "${{ steps.version.outputs.chart_version }}" - name: Upload helm package as artifact - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: helm-package path: helm/rustfs/*.tgz @@ -129,7 +129,7 @@ jobs: token: ${{ secrets.RUSTFS_HELM_PACKAGE }} - name: Download helm package - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: helm-package path: ./ diff --git a/.github/workflows/minio-interop.yml b/.github/workflows/minio-interop.yml index ffd9c60a4..9a5315c7c 100644 --- a/.github/workflows/minio-interop.yml +++ b/.github/workflows/minio-interop.yml @@ -83,7 +83,7 @@ jobs: INTEROP_REQUIRED_TESTS: '["reads_minio_generated_sse_s3_multipart_fixture", "reads_minio_generated_sse_kms_multipart_fixture", "rejects_minio_generated_sse_s3_fixture_with_wrong_kms_key", "rejects_minio_generated_sse_s3_fixture_with_truncated_ciphertext"]' steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -137,7 +137,7 @@ jobs: contents: read issues: write steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + - uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Open or update failure-tracking issue diff --git a/.github/workflows/mint.yml b/.github/workflows/mint.yml index b0b5a9af7..87e0de0c9 100644 --- a/.github/workflows/mint.yml +++ b/.github/workflows/mint.yml @@ -117,7 +117,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 120 steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + - uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -246,7 +246,7 @@ jobs: - name: Upload artifacts if: always() && env.ACT != 'true' - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: mint path: artifacts/** @@ -264,7 +264,7 @@ jobs: contents: read issues: write steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + - uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Open or update failure-tracking issue diff --git a/.github/workflows/nightly-gnu.yml b/.github/workflows/nightly-gnu.yml index bc7b73a33..f7c1654aa 100644 --- a/.github/workflows/nightly-gnu.yml +++ b/.github/workflows/nightly-gnu.yml @@ -51,7 +51,7 @@ jobs: source_ref: ${{ steps.source.outputs.ref }} steps: - name: Checkout selected source - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false ref: ${{ env.NIGHTLY_BUILD_REF }} @@ -71,7 +71,7 @@ jobs: FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true" steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false ref: ${{ needs.resolve-source.outputs.source_sha }} @@ -237,12 +237,12 @@ jobs: echo "rpm_file=$RPM_FILE" >> "$GITHUB_OUTPUT" - name: Upload DEB artifact - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: ${{ steps.deb.outputs.deb_file }} path: ${{ steps.deb.outputs.deb_file }} - name: Upload RPM artifact - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: ${{ steps.rpm.outputs.rpm_file }} path: ${{ steps.rpm.outputs.rpm_file }} @@ -328,7 +328,7 @@ jobs: - name: Upload nightly candidate manifest if: ${{ steps.publish.outputs.candidate_file != '' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: nightly-candidate-${{ github.run_id }}-${{ github.run_attempt }} path: ${{ steps.publish.outputs.candidate_file }} @@ -383,7 +383,7 @@ jobs: NO_PROXY: 127.0.0.1,localhost steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false ref: ${{ needs.resolve-source.outputs.source_sha }} @@ -473,7 +473,7 @@ jobs: NO_PROXY: 127.0.0.1,localhost steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false ref: ${{ needs.resolve-source.outputs.source_sha }} @@ -501,7 +501,7 @@ jobs: contents: read issues: write steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + - uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Open or update failure-tracking issue diff --git a/.github/workflows/nix-flake-update.yml b/.github/workflows/nix-flake-update.yml index c694a2889..87b114d96 100644 --- a/.github/workflows/nix-flake-update.yml +++ b/.github/workflows/nix-flake-update.yml @@ -46,17 +46,17 @@ jobs: # workflow_dispatch run confirms it (rustfs/backlog#1602). - name: Install Nix - uses: DeterminateSystems/determinate-nix-action@629b284231c2a82554b724e357e47fc6020833c8 # v3 + uses: DeterminateSystems/determinate-nix-action@8d87e8d5e5b8a8309d4281094560f127d9a265f1 # v3.22.5 - name: Cache Nix - uses: DeterminateSystems/flakehub-cache-action@1f9a51a2959d3e26c7838c6f3bf9f48acae525ea # v3.20.0 + uses: DeterminateSystems/flakehub-cache-action@83282a8aef353db1d659d3bacf4a28b6683de0b3 # v3.22.5 - name: Check Nix flake inputs - uses: DeterminateSystems/flake-checker-action@3164002371bc90729c68af0e24d5aacf20d7c9f6 # v12 + uses: DeterminateSystems/flake-checker-action@786422608c7bded2bbc9741ad9f91356842bf520 # v14 - name: Update flake.lock id: update - uses: DeterminateSystems/update-flake-lock@fd9359ac79d0e912f1b4b947a48470b3e2799b56 # main + uses: DeterminateSystems/update-flake-lock@da03c0f078bc4b2c37ee4f7e072d34bf8f188bb3 # v29 with: git-author-name: houseme git-author-email: housemecn@gmail.com diff --git a/.github/workflows/nix.yml b/.github/workflows/nix.yml index c9dafc14a..ed8183232 100644 --- a/.github/workflows/nix.yml +++ b/.github/workflows/nix.yml @@ -77,7 +77,7 @@ jobs: persist-credentials: false - name: Install Nix - uses: DeterminateSystems/determinate-nix-action@4eea0b33e3d1f02ecfe37cf16e7204c424009606 # v3.21.0 + uses: DeterminateSystems/determinate-nix-action@8d87e8d5e5b8a8309d4281094560f127d9a265f1 # v3.22.5 with: github-token: ${{ secrets.GITHUB_TOKEN }} extra-conf: | @@ -86,10 +86,10 @@ jobs: max-jobs = 1 - name: Cache Nix - uses: DeterminateSystems/flakehub-cache-action@c01e819d047464c3edf6ba778f075952af5a3aa7 # v3.21.0 + uses: DeterminateSystems/flakehub-cache-action@83282a8aef353db1d659d3bacf4a28b6683de0b3 # v3.22.5 - name: Check Nix Flake Inputs - uses: DeterminateSystems/flake-checker-action@3164002371bc90729c68af0e24d5aacf20d7c9f6 # v12 + uses: DeterminateSystems/flake-checker-action@786422608c7bded2bbc9741ad9f91356842bf520 # v14 with: fail-mode: true ignore-missing-flake-lock: false diff --git a/.github/workflows/oidc-keycloak.yml b/.github/workflows/oidc-keycloak.yml index b221f49aa..eaa141043 100644 --- a/.github/workflows/oidc-keycloak.yml +++ b/.github/workflows/oidc-keycloak.yml @@ -82,7 +82,7 @@ jobs: - name: Upload service logs if: failure() - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: oidc-keycloak-live-${{ github.run_number }} path: ${{ runner.temp }}/rustfs-keycloak-live-*/**/*.log diff --git a/.github/workflows/on-demand-migration-interop.yml b/.github/workflows/on-demand-migration-interop.yml index d2971e441..9c2278283 100644 --- a/.github/workflows/on-demand-migration-interop.yml +++ b/.github/workflows/on-demand-migration-interop.yml @@ -93,7 +93,7 @@ jobs: NEXTEST_LISTING: ${{ github.workspace }}/artifacts/odm-interop/minio/selection.json steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -166,7 +166,7 @@ jobs: - name: Upload the MinIO interop report if: always() - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: odm-interop-minio-${{ github.run_number }}-${{ github.run_attempt }} path: | @@ -237,7 +237,7 @@ jobs: - name: Checkout repository if: steps.credentials.outputs.present == 'true' - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -286,7 +286,7 @@ jobs: - name: Upload the ${{ matrix.provider }} interop report if: always() && steps.credentials.outputs.present == 'true' - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: odm-interop-${{ matrix.provider }}-${{ github.run_number }}-${{ github.run_attempt }} path: | @@ -306,7 +306,7 @@ jobs: contents: read issues: write steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + - uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Open or update failure-tracking issue diff --git a/.github/workflows/package.yml b/.github/workflows/package.yml index cbcc2b88e..3cb2ba25e 100644 --- a/.github/workflows/package.yml +++ b/.github/workflows/package.yml @@ -268,7 +268,7 @@ jobs: rpm_depends: "" steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -289,7 +289,7 @@ jobs: printf '%s\n' "$normalized" >> "$GITHUB_OUTPUT" - name: Download binary artifact from build run - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: pattern: ${{ matrix.artifact_name }}* path: ./binary-artifact @@ -495,7 +495,7 @@ jobs: echo "✅ RPM built: $RPM_FILE" - name: Upload packages to artifacts - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: packages-${{ matrix.arch }}-${{ matrix.libc }} path: | diff --git a/.github/workflows/performance-ab.yml b/.github/workflows/performance-ab.yml index af82dd382..d402ca636 100644 --- a/.github/workflows/performance-ab.yml +++ b/.github/workflows/performance-ab.yml @@ -57,7 +57,7 @@ jobs: timeout-minutes: 180 steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false fetch-depth: 0 # baseline may be an earlier successful scheduled head @@ -94,7 +94,7 @@ jobs: - name: Find last successful scheduled baseline id: scheduled_baseline if: github.event_name == 'schedule' - uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8 + uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: result-encoding: string script: | @@ -271,7 +271,7 @@ jobs: - name: Upload A/B results if: always() - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: hotpath-warp-ab-${{ github.run_number }} # Includes per-cell median_summary.csv / baseline_compare.csv, both gates, @@ -372,7 +372,7 @@ jobs: contents: read issues: write steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + - uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Open or update failure-tracking issue diff --git a/.github/workflows/runner-hygiene.yml b/.github/workflows/runner-hygiene.yml index 8b642bd74..22d797d5f 100644 --- a/.github/workflows/runner-hygiene.yml +++ b/.github/workflows/runner-hygiene.yml @@ -47,7 +47,7 @@ jobs: timeout-minutes: 15 steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -72,7 +72,7 @@ jobs: contents: read issues: write steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + - uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Open or update failure-tracking issue diff --git a/.github/workflows/rustfs-fault-tolerance-matrix.yml b/.github/workflows/rustfs-fault-tolerance-matrix.yml index ffd216cc0..8d2a9ff8c 100644 --- a/.github/workflows/rustfs-fault-tolerance-matrix.yml +++ b/.github/workflows/rustfs-fault-tolerance-matrix.yml @@ -95,7 +95,7 @@ jobs: - name: Checkout auto-testing scripts timeout-minutes: 5 - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: repository: rustfs/auto-testing ref: ${{ inputs.auto_testing_ref }} @@ -204,7 +204,7 @@ jobs: - name: Upload test logs & evidence timeout-minutes: 2 if: ${{ always() && steps.evidence.outcome == 'success' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: rustfs-fault-tolerance-matrix-${{ github.run_id }}-${{ github.run_attempt }} path: | diff --git a/.github/workflows/rustfs-fault-tolerance-test.yml b/.github/workflows/rustfs-fault-tolerance-test.yml index 7127a2e73..f6e613a27 100644 --- a/.github/workflows/rustfs-fault-tolerance-test.yml +++ b/.github/workflows/rustfs-fault-tolerance-test.yml @@ -83,7 +83,7 @@ jobs: if: ${{ inputs.chain_manifest != '' || github.event_name == 'workflow_dispatch' || github.event_name == 'repository_dispatch' }} steps: - name: Checkout repository (for report parser) - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -113,7 +113,7 @@ jobs: - name: Checkout auto-testing scripts timeout-minutes: 5 - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: repository: rustfs/auto-testing ref: ${{ steps.chain.outputs.testing_sha || inputs.auto_testing_ref || 'main' }} @@ -294,7 +294,7 @@ jobs: - name: Upload test logs & evidence timeout-minutes: 2 if: ${{ always() && steps.evidence.outcome == 'success' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: rustfs-fault-tolerance-${{ github.run_id }}-${{ github.run_attempt }} path: | @@ -386,7 +386,7 @@ jobs: - name: Upload chain evidence if: ${{ always() && steps.chain_record.outputs.written == 'true' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: functional-chain-fault-tolerance-${{ github.run_id }}-${{ github.run_attempt }} path: ${{ runner.temp }}/chain-fault-tolerance-${{ github.run_id }}-${{ github.run_attempt }}/fault-tolerance.json diff --git a/.github/workflows/rustfs-functional-chain.yml b/.github/workflows/rustfs-functional-chain.yml index 8a6fe0848..3e14e17b2 100644 --- a/.github/workflows/rustfs-functional-chain.yml +++ b/.github/workflows/rustfs-functional-chain.yml @@ -63,7 +63,7 @@ jobs: CHAIN_OUTPUT: ${{ runner.temp }}/chain-candidate.json run: python3 scripts/resolve_functional_candidate.py - name: Retain candidate identity - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: functional-candidate-${{ github.run_id }}-${{ github.run_attempt }} path: ${{ runner.temp }}/chain-candidate.json @@ -197,7 +197,7 @@ jobs: - name: Download suite evidence id: download continue-on-error: true - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: pattern: functional-chain-*-${{ github.run_id }}-${{ github.run_attempt }} path: ${{ runner.temp }}/chain-evidence @@ -213,7 +213,7 @@ jobs: --output "${RUNNER_TEMP}/chain-report.json" - name: Retain chain report regardless of test verdict if: always() - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: functional-chain-report-${{ github.run_id }}-${{ github.run_attempt }} path: | @@ -231,7 +231,7 @@ jobs: --directory "${RUNNER_TEMP}/chain-evidence" --output "${RUNNER_TEMP}/chain-complete.json" - name: Upload complete-chain evidence - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: functional-chain-complete-${{ github.run_id }}-${{ github.run_attempt }} path: ${{ runner.temp }}/chain-complete.json diff --git a/.github/workflows/rustfs-heal-test.yml b/.github/workflows/rustfs-heal-test.yml index 0e18bfc6b..81d78d6e1 100644 --- a/.github/workflows/rustfs-heal-test.yml +++ b/.github/workflows/rustfs-heal-test.yml @@ -66,7 +66,7 @@ jobs: if: ${{ inputs.chain_manifest != '' || github.event_name == 'workflow_dispatch' || github.event_name == 'repository_dispatch' }} steps: - name: Checkout chain tooling - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -93,7 +93,7 @@ jobs: run: python3 scripts/functional_chain_evidence.py consume - name: Checkout auto-testing scripts - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: repository: rustfs/auto-testing ref: ${{ steps.chain.outputs.testing_sha || 'main' }} @@ -366,7 +366,7 @@ jobs: - name: Upload test logs timeout-minutes: 2 if: ${{ always() && steps.evidence.outcome == 'success' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: rustfs-heal-test-${{ github.run_id }}-${{ github.run_attempt }} path: | @@ -467,7 +467,7 @@ jobs: - name: Upload chain evidence if: ${{ always() && steps.chain_record.outputs.written == 'true' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: functional-chain-heal-${{ github.run_id }}-${{ github.run_attempt }} path: ${{ runner.temp }}/chain-heal-${{ github.run_id }}-${{ github.run_attempt }}/heal.json diff --git a/.github/workflows/rustfs-kms-test.yml b/.github/workflows/rustfs-kms-test.yml index ab5aa7f8e..7c86f3d09 100644 --- a/.github/workflows/rustfs-kms-test.yml +++ b/.github/workflows/rustfs-kms-test.yml @@ -59,7 +59,7 @@ jobs: if: ${{ inputs.chain_manifest != '' || github.event_name == 'workflow_dispatch' || github.event_name == 'repository_dispatch' }} steps: - name: Checkout repository (for report parser) - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -85,7 +85,7 @@ jobs: run: python3 scripts/functional_chain_evidence.py consume - name: Checkout auto-testing scripts - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: repository: rustfs/auto-testing ref: ${{ steps.chain.outputs.testing_sha || 'main' }} @@ -315,7 +315,7 @@ jobs: - name: Upload report and logs timeout-minutes: 2 if: ${{ always() && steps.evidence.outcome == 'success' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: rustfs-kms-test-${{ github.run_id }}-${{ github.run_attempt }} path: | @@ -414,7 +414,7 @@ jobs: - name: Upload chain evidence if: ${{ always() && steps.chain_record.outputs.written == 'true' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: functional-chain-kms-${{ github.run_id }}-${{ github.run_attempt }} path: ${{ runner.temp }}/chain-kms-${{ github.run_id }}-${{ github.run_attempt }}/kms.json diff --git a/.github/workflows/rustfs-performance-test.yml b/.github/workflows/rustfs-performance-test.yml index 64570c3a0..9c8bb90a0 100644 --- a/.github/workflows/rustfs-performance-test.yml +++ b/.github/workflows/rustfs-performance-test.yml @@ -93,7 +93,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 5 steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + - uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Check performance runner before entering its queue @@ -116,7 +116,7 @@ jobs: if: ${{ inputs.chain_manifest != '' || github.event_name == 'workflow_dispatch' || github.event_name == 'repository_dispatch' }} steps: - name: Checkout chain tooling - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -144,7 +144,7 @@ jobs: run: python3 scripts/functional_chain_evidence.py consume - name: Checkout auto-testing scripts - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: repository: rustfs/auto-testing ref: ${{ steps.chain.outputs.testing_sha || 'main' }} @@ -307,7 +307,7 @@ jobs: - name: Upload test logs & results if: ${{ always() && steps.evidence.outcome == 'success' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: rustfs-perf-test-${{ github.run_id }}-${{ github.run_attempt }} path: | @@ -349,7 +349,7 @@ jobs: - name: Upload chain evidence if: ${{ always() && steps.chain_record.outputs.written == 'true' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: functional-chain-performance-${{ github.run_id }}-${{ github.run_attempt }} path: ${{ runner.temp }}/chain-performance-${{ github.run_id }}-${{ github.run_attempt }}/performance.json diff --git a/.github/workflows/rustfs-pool-expand-test.yml b/.github/workflows/rustfs-pool-expand-test.yml index 94f2e27ee..eff8b5330 100644 --- a/.github/workflows/rustfs-pool-expand-test.yml +++ b/.github/workflows/rustfs-pool-expand-test.yml @@ -92,7 +92,7 @@ jobs: RUSTFS_POOL_NODE_ENDPOINTS: ${{ secrets.RUSTFS_POOL_NODE_ENDPOINTS || vars.RUSTFS_POOL_NODE_ENDPOINTS || 'http://rustfs-node1:9000 http://rustfs-node2:9000 http://rustfs-node3:9000 http://rustfs-node4:9000' }} steps: - name: Checkout chain tooling - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -104,7 +104,7 @@ jobs: run: python3 scripts/functional_chain_evidence.py consume - name: Checkout auto-testing scripts - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: repository: rustfs/auto-testing ref: ${{ steps.chain.outputs.testing_sha || 'main' }} @@ -656,7 +656,7 @@ jobs: - name: Upload test logs timeout-minutes: 2 if: always() - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: rustfs-pool-test-${{ github.run_id }}-${{ github.run_attempt }} path: ${{ runner.temp }}/rustfs-pool-${{ github.run_id }}-${{ github.run_attempt }} @@ -764,7 +764,7 @@ jobs: - name: Upload chain evidence if: ${{ always() && steps.chain_record.outputs.written == 'true' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: functional-chain-pool-${{ github.run_id }}-${{ github.run_attempt }} path: ${{ runner.temp }}/chain-pool-${{ github.run_id }}-${{ github.run_attempt }}/pool.json diff --git a/.github/workflows/rustfs-replication-test.yml b/.github/workflows/rustfs-replication-test.yml index f30f7e7c5..c8d69162a 100644 --- a/.github/workflows/rustfs-replication-test.yml +++ b/.github/workflows/rustfs-replication-test.yml @@ -71,7 +71,7 @@ jobs: if: ${{ inputs.chain_manifest != '' || github.event_name == 'workflow_dispatch' || github.event_name == 'repository_dispatch' }} steps: - name: Checkout repository (for report parser) - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -97,7 +97,7 @@ jobs: run: python3 scripts/functional_chain_evidence.py consume - name: Checkout auto-testing scripts - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: repository: rustfs/auto-testing ref: ${{ steps.chain.outputs.testing_sha || 'main' }} @@ -323,7 +323,7 @@ jobs: - name: Upload report and logs timeout-minutes: 2 if: ${{ always() && steps.evidence.outcome == 'success' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: rustfs-replication-${{ github.run_id }}-${{ github.run_attempt }} path: | @@ -419,7 +419,7 @@ jobs: - name: Upload chain evidence if: ${{ always() && steps.chain_record.outputs.written == 'true' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: functional-chain-replication-${{ github.run_id }}-${{ github.run_attempt }} path: ${{ runner.temp }}/chain-replication-${{ github.run_id }}-${{ github.run_attempt }}/replication.json diff --git a/.github/workflows/rustfs-s3-compat-test.yml b/.github/workflows/rustfs-s3-compat-test.yml index fc9238f4a..4bcf37c97 100644 --- a/.github/workflows/rustfs-s3-compat-test.yml +++ b/.github/workflows/rustfs-s3-compat-test.yml @@ -47,7 +47,7 @@ jobs: if: ${{ inputs.chain_manifest != '' || github.event_name == 'workflow_dispatch' || github.event_name == 'repository_dispatch' }} steps: - name: Checkout repository (for report parser) - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -73,7 +73,7 @@ jobs: run: python3 scripts/functional_chain_evidence.py consume - name: Checkout auto-testing scripts - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: repository: rustfs/auto-testing ref: ${{ steps.chain.outputs.testing_sha || 'main' }} @@ -292,7 +292,7 @@ jobs: - name: Upload report and logs timeout-minutes: 2 if: ${{ always() && steps.evidence.outcome == 'success' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: rustfs-s3-compat-${{ github.run_id }}-${{ github.run_attempt }} path: | @@ -391,7 +391,7 @@ jobs: - name: Upload chain evidence if: ${{ always() && steps.chain_record.outputs.written == 'true' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: functional-chain-s3-${{ github.run_id }}-${{ github.run_attempt }} path: ${{ runner.temp }}/chain-s3-${{ github.run_id }}-${{ github.run_attempt }}/s3.json diff --git a/.github/workflows/rustfs-security-test.yml b/.github/workflows/rustfs-security-test.yml index 3d7bcd8a1..f4d5aca2b 100644 --- a/.github/workflows/rustfs-security-test.yml +++ b/.github/workflows/rustfs-security-test.yml @@ -87,7 +87,7 @@ jobs: # the workspace root would wipe the auto-testing clone above (that is # exactly how run 33934141181 lost rustfs-security-test.sh). - name: Checkout repository (for the OIDC live gate script) - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false path: rustfs-repo @@ -109,7 +109,7 @@ jobs: run: python3 scripts/functional_chain_evidence.py consume - name: Checkout auto-testing scripts - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: repository: rustfs/auto-testing ref: ${{ steps.chain.outputs.testing_sha || 'main' }} @@ -325,7 +325,7 @@ jobs: - name: Upload report and logs timeout-minutes: 2 if: ${{ always() && steps.evidence.outcome == 'success' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: rustfs-security-test-${{ github.run_id }}-${{ github.run_attempt }} path: | @@ -395,7 +395,7 @@ jobs: - name: Upload chain evidence if: ${{ always() && steps.chain_record.outputs.written == 'true' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: functional-chain-security-${{ github.run_id }}-${{ github.run_attempt }} path: ${{ runner.temp }}/chain-security-${{ github.run_id }}-${{ github.run_attempt }}/security.json diff --git a/.github/workflows/rustfs-storage-test.yml b/.github/workflows/rustfs-storage-test.yml index 5e4a7441d..f8bae5cc9 100644 --- a/.github/workflows/rustfs-storage-test.yml +++ b/.github/workflows/rustfs-storage-test.yml @@ -56,7 +56,7 @@ jobs: if: ${{ inputs.chain_manifest != '' || github.event_name == 'workflow_dispatch' || github.event_name == 'repository_dispatch' }} steps: - name: Checkout repository (for report parser) - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -82,7 +82,7 @@ jobs: run: python3 scripts/functional_chain_evidence.py consume - name: Checkout auto-testing scripts - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: repository: rustfs/auto-testing ref: ${{ steps.chain.outputs.testing_sha || 'main' }} @@ -307,7 +307,7 @@ jobs: - name: Upload report and logs timeout-minutes: 2 if: ${{ always() && steps.evidence.outcome == 'success' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: rustfs-storage-${{ github.run_id }}-${{ github.run_attempt }} path: | @@ -406,7 +406,7 @@ jobs: - name: Upload chain evidence if: ${{ always() && steps.chain_record.outputs.written == 'true' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: functional-chain-storage-${{ github.run_id }}-${{ github.run_attempt }} path: ${{ runner.temp }}/chain-storage-${{ github.run_id }}-${{ github.run_attempt }}/storage.json diff --git a/.github/workflows/rustfs-table-test.yml b/.github/workflows/rustfs-table-test.yml index a45b6963d..60f562168 100644 --- a/.github/workflows/rustfs-table-test.yml +++ b/.github/workflows/rustfs-table-test.yml @@ -46,7 +46,7 @@ jobs: timeout-minutes: 60 steps: - name: Checkout repository (for report parser) - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -73,7 +73,7 @@ jobs: - name: Checkout auto-testing scripts timeout-minutes: 5 - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: repository: rustfs/auto-testing ref: ${{ steps.chain.outputs.testing_sha || 'main' }} @@ -281,7 +281,7 @@ jobs: - name: Upload report and logs timeout-minutes: 2 if: ${{ always() && steps.evidence.outcome == 'success' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: rustfs-table-test-${{ github.run_id }}-${{ github.run_attempt }} path: | @@ -353,7 +353,7 @@ jobs: - name: Upload chain evidence if: ${{ always() && steps.chain_record.outputs.written == 'true' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: functional-chain-table-${{ github.run_id }}-${{ github.run_attempt }} path: ${{ runner.temp }}/chain-table-${{ github.run_id }}-${{ github.run_attempt }}/table.json diff --git a/.github/workflows/rustfs-tier-test.yml b/.github/workflows/rustfs-tier-test.yml index a78f7f5bd..05dcfdede 100644 --- a/.github/workflows/rustfs-tier-test.yml +++ b/.github/workflows/rustfs-tier-test.yml @@ -71,7 +71,7 @@ jobs: if: ${{ inputs.chain_manifest != '' || github.event_name == 'workflow_dispatch' || github.event_name == 'repository_dispatch' }} steps: - name: Checkout chain tooling - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -95,7 +95,7 @@ jobs: run: python3 scripts/functional_chain_evidence.py consume - name: Checkout auto-testing scripts - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: repository: rustfs/auto-testing ref: ${{ steps.chain.outputs.testing_sha || 'main' }} @@ -460,7 +460,7 @@ jobs: - name: Upload report and logs timeout-minutes: 2 if: ${{ always() && steps.evidence.outcome == 'success' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: rustfs-tier-test-${{ github.run_id }}-${{ github.run_attempt }} path: ${{ env.TIER_ARTIFACTS_DIR }}/ @@ -734,7 +734,7 @@ jobs: - name: Upload chain evidence if: ${{ always() && steps.chain_record.outputs.written == 'true' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: functional-chain-tier-${{ github.run_id }}-${{ github.run_attempt }} path: ${{ runner.temp }}/chain-tier-${{ github.run_id }}-${{ github.run_attempt }}/tier.json diff --git a/.github/workflows/rustfs-upgrade-test.yml b/.github/workflows/rustfs-upgrade-test.yml index caa63d89c..f6690c480 100644 --- a/.github/workflows/rustfs-upgrade-test.yml +++ b/.github/workflows/rustfs-upgrade-test.yml @@ -89,7 +89,7 @@ jobs: if: ${{ inputs.chain_manifest != '' || github.event_name == 'workflow_dispatch' || github.event_name == 'repository_dispatch' }} steps: - name: Checkout repository (for report parser) - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -115,7 +115,7 @@ jobs: run: python3 scripts/functional_chain_evidence.py consume - name: Checkout auto-testing scripts - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: repository: rustfs/auto-testing ref: ${{ steps.chain.outputs.testing_sha || 'main' }} @@ -400,7 +400,7 @@ jobs: - name: Upload report and logs timeout-minutes: 2 if: ${{ always() && steps.evidence.outcome == 'success' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: rustfs-upgrade-test-${{ github.run_id }}-${{ github.run_attempt }} path: | @@ -503,7 +503,7 @@ jobs: - name: Upload chain evidence if: ${{ always() && steps.chain_record.outputs.written == 'true' }} - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: functional-chain-upgrade-${{ github.run_id }}-${{ github.run_attempt }} path: ${{ runner.temp }}/chain-upgrade-${{ github.run_id }}-${{ github.run_attempt }}/upgrade.json diff --git a/.github/workflows/scheduled-validation-freshness.yml b/.github/workflows/scheduled-validation-freshness.yml index 964ed8430..59f891cce 100644 --- a/.github/workflows/scheduled-validation-freshness.yml +++ b/.github/workflows/scheduled-validation-freshness.yml @@ -36,7 +36,7 @@ jobs: contents: read issues: write steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + - uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Check latest scheduled runs diff --git a/.github/workflows/scheduled-validation-watchdog.yml b/.github/workflows/scheduled-validation-watchdog.yml index 3f9facbc6..9927e7310 100644 --- a/.github/workflows/scheduled-validation-watchdog.yml +++ b/.github/workflows/scheduled-validation-watchdog.yml @@ -49,7 +49,7 @@ jobs: contents: read issues: write steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + - uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Open or update incomplete-run issue diff --git a/.github/workflows/stale.yml b/.github/workflows/stale.yml index 6eb903db8..b1d54e00f 100644 --- a/.github/workflows/stale.yml +++ b/.github/workflows/stale.yml @@ -29,7 +29,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 30 steps: - - uses: actions/stale@5bef64f19d7facfb25b37b414482c7164d639639 # v9 + - uses: actions/stale@4391f3da665fdf50b6810c1a66712fb9ba21aa93 # v11.0.0 with: repo-token: ${{ secrets.GITHUB_TOKEN }} stale-issue-message: 'This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs.' diff --git a/.github/workflows/targets-integration.yml b/.github/workflows/targets-integration.yml index 5b73dda53..c5354d254 100644 --- a/.github/workflows/targets-integration.yml +++ b/.github/workflows/targets-integration.yml @@ -52,7 +52,7 @@ jobs: RUSTFS_TEST_NATS_URL: nats://127.0.0.1:4222 steps: - name: Checkout repository - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false @@ -166,7 +166,7 @@ jobs: - name: Upload target integration diagnostics if: always() - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: targets-integration-${{ github.run_number }}-${{ github.run_attempt }} path: artifacts/targets-live @@ -183,7 +183,7 @@ jobs: contents: read issues: write steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + - uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false - name: Open or update failure-tracking issue diff --git a/scripts/check_test_wiring.py b/scripts/check_test_wiring.py index 5d21313b3..976eb3f20 100755 --- a/scripts/check_test_wiring.py +++ b/scripts/check_test_wiring.py @@ -512,6 +512,18 @@ SCHEDULED_ALERT_CHECKOUT_OVERRIDES = { ".github/workflows/audit.yml": "actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a", ".github/workflows/coverage.yml": "actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a", ".github/workflows/e2e-replication-nightly.yml": "actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a", + ".github/workflows/e2e-distributed.yml": "actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a", + ".github/workflows/e2e-s3tests.yml": "actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a", + ".github/workflows/mint.yml": "actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a", + ".github/workflows/minio-interop.yml": "actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a", + ".github/workflows/build.yml": "actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a", + ".github/workflows/ci.yml": "actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a", + ".github/workflows/fuzz.yml": "actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a", + ".github/workflows/nightly-gnu.yml": "actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a", + ".github/workflows/performance-ab.yml": "actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a", + ".github/workflows/runner-hygiene.yml": "actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a", + ".github/workflows/scheduled-validation-watchdog.yml": "actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a", + ".github/workflows/scheduled-validation-freshness.yml": "actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a", } @@ -1037,7 +1049,10 @@ def check_quick_checks(root: Path) -> list[str]: yaml_scalar_continues(job, index, 4) for index in conditions ): errors.append(f"{relative}: Quick Checks job must not add dependencies, bypass failures, or change its event condition") - checkout = workflow_step_block(job, "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0") + checkout_ref = SCHEDULED_ALERT_CHECKOUT_OVERRIDES.get( + relative, "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" + ) + checkout = workflow_step_block(job, checkout_ref) action = workflow_step_block(job, "./.github/actions/quick-checks") if checkout is None or action is None: errors.append(f"{relative}: Quick Checks requires checkout and the shared quick-checks action") @@ -1227,13 +1242,17 @@ def check_scheduled_alerts(root: Path) -> list[str]: errors.append(".github/workflows/scheduled-validation-watchdog.yml: missing alert-on-incomplete-run job") return errors watchdog_job = "\n".join(line.split("#", 1)[0] for line in watchdog_job_lines) + watchdog_checkout_ref = SCHEDULED_ALERT_CHECKOUT_OVERRIDES.get( + ".github/workflows/scheduled-validation-watchdog.yml", + "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0", + ) required = ( "github.event.workflow_run.event == 'schedule'", "github.event.workflow_run.conclusion != 'success'", "github.event.workflow_run.conclusion != 'failure'", "actions: read", "issues: write", - "uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0", + f"uses: {watchdog_checkout_ref}", "uses: ./.github/actions/schedule-failure-issue", "github-token: ${{ secrets.BACKLOG_ISSUE_TOKEN }}", "workflow-name: ${{ github.event.workflow_run.name }}", @@ -1264,6 +1283,7 @@ def check_scheduled_alerts(root: Path) -> list[str]: "source-ref-name: ${{ github.event.workflow_run.head_branch }}", "source-sha: ${{ github.event.workflow_run.head_sha }}", ), + checkout_ref=watchdog_checkout_ref, ) ) @@ -1278,12 +1298,16 @@ def check_scheduled_alerts(root: Path) -> list[str]: errors.append(".github/workflows/scheduled-validation-freshness.yml: missing check-freshness job") return errors freshness_job = "\n".join(line.split("#", 1)[0] for line in freshness_job_lines) + freshness_checkout_ref = SCHEDULED_ALERT_CHECKOUT_OVERRIDES.get( + ".github/workflows/scheduled-validation-freshness.yml", + "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0", + ) required = ( "python3 scripts/check_scheduled_validation_freshness.py", "actions: read", "issues: write", "if: failure()", - "uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0", + f"uses: {freshness_checkout_ref}", "uses: ./.github/actions/schedule-failure-issue", "github-token: ${{ secrets.BACKLOG_ISSUE_TOKEN }}", "details-file: ${{ runner.temp }}/scheduled-validation-freshness.md", @@ -1304,6 +1328,7 @@ def check_scheduled_alerts(root: Path) -> list[str]: "github-token: ${{ secrets.BACKLOG_ISSUE_TOKEN }}", "details-file: ${{ runner.temp }}/scheduled-validation-freshness.md", ), + checkout_ref=freshness_checkout_ref, ) ) if not (root / "scripts/check_scheduled_validation_freshness.py").is_file(): @@ -3480,7 +3505,7 @@ class SelfTests(unittest.TestCase): root = Path(tmp) caller = ( "jobs:\n quick-checks:\n steps:\n" - " - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0\n" + " - uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a\n" " with:\n persist-credentials: false\n" " - uses: ./.github/actions/quick-checks\n" ) @@ -5870,6 +5895,16 @@ class SelfTests(unittest.TestCase): ".github/workflows/audit.yml", ".github/workflows/coverage.yml", ".github/workflows/e2e-replication-nightly.yml", + ".github/workflows/e2e-distributed.yml", + ".github/workflows/e2e-s3tests.yml", + ".github/workflows/mint.yml", + ".github/workflows/minio-interop.yml", + ".github/workflows/build.yml", + ".github/workflows/ci.yml", + ".github/workflows/fuzz.yml", + ".github/workflows/nightly-gnu.yml", + ".github/workflows/performance-ab.yml", + ".github/workflows/runner-hygiene.yml", ) with tempfile.TemporaryDirectory() as tmp: root = Path(tmp) @@ -5897,6 +5932,8 @@ class SelfTests(unittest.TestCase): f'on:\n schedule:\n - cron: "{index} {index} * * *"\n' f'jobs:\n{workflow_alert}' ) + watchdog_checkout = new_checkout + freshness_checkout = new_checkout watchdog = root / ".github/workflows/scheduled-validation-watchdog.yml" watchdog.write_text( "on:\n workflow_run:\n workflows:\n" @@ -5910,7 +5947,7 @@ class SelfTests(unittest.TestCase): + " actions: read\n" + " issues: write\n" + " steps:\n" - + " - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0\n" + + f" - uses: {watchdog_checkout}\n" + " - uses: ./.github/actions/schedule-failure-issue\n" + " with:\n" + " github-token: ${{ secrets.BACKLOG_ISSUE_TOKEN }}\n" @@ -5929,7 +5966,7 @@ class SelfTests(unittest.TestCase): " actions: read\n" " issues: write\n" " steps:\n" - " - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0\n" + f" - uses: {freshness_checkout}\n" " - run: python3 scripts/check_scheduled_validation_freshness.py\n" " - uses: ./.github/actions/schedule-failure-issue\n" " if: failure()\n" @@ -6024,12 +6061,12 @@ class SelfTests(unittest.TestCase): ("actions: read", "actions: none"), ("issues: write", "issues: read"), ( - "uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0", + f"uses: {watchdog_checkout}", "uses: actions/checkout@missing", ), ( - " - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0\n", - " - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0\n" + f" - uses: {watchdog_checkout}\n", + f" - uses: {watchdog_checkout}\n" " if: github.event_name == 'workflow_dispatch'\n", ), ( @@ -6132,15 +6169,15 @@ class SelfTests(unittest.TestCase): self.assertEqual(len(check_scheduled_alerts(root)), 1) freshness.write_text( freshness_original.replace( - "uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0", + f"uses: {freshness_checkout}", "uses: actions/checkout@missing", ) ) self.assertEqual(len(check_scheduled_alerts(root)), 1) freshness.write_text( freshness_original.replace( - " - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0\n", - " - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0\n" + f" - uses: {freshness_checkout}\n", + f" - uses: {freshness_checkout}\n" " if: github.event_name == 'workflow_dispatch'\n", ) )