diff --git a/.github/workflows/python-release.yml b/.github/workflows/python-release.yml index 28abd7cd..345fe1c6 100644 --- a/.github/workflows/python-release.yml +++ b/.github/workflows/python-release.yml @@ -38,11 +38,11 @@ jobs: # to that, because it would have to name a version nothing has computed # yet — so `py-v` is an output, pointing at exactly the tree that # was published. - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: ref: 'main' fetch-depth: 0 - - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: '3.12' # Consumes changes/ — bumps `__version__` by the strongest level pending diff --git a/.github/workflows/python.yml b/.github/workflows/python.yml index 23a79a4c..501daef2 100644 --- a/.github/workflows/python.yml +++ b/.github/workflows/python.yml @@ -44,10 +44,10 @@ jobs: steps: # Full history: the change-fragment gate diffs this branch against the # base, which a depth-1 checkout cannot see. - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 - - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: ${{ matrix.python-version }} # A source change with no fragment is a release that cannot describe