diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 41c2c3d..ee377f3 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -39,7 +39,7 @@ jobs: - uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable with: components: rustfmt, clippy - - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 + - uses: Swatinem/rust-cache@f0d9c3887740aee45f6153b24b3a6b815192ec16 # v2 - name: Check formatting run: cargo fmt --all -- --check @@ -53,7 +53,7 @@ jobs: - uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable with: components: clippy, rustfmt - - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 + - uses: Swatinem/rust-cache@f0d9c3887740aee45f6153b24b3a6b815192ec16 # v2 - name: Clippy (fail on warnings) run: cargo clippy --workspace --all-targets --all-features -- -D warnings @@ -64,7 +64,7 @@ jobs: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - - uses: taiki-e/install-action@6cd13508893c0e7eab5f273c2575d3859bd7229a # v2.86.6 + - uses: taiki-e/install-action@d438492cf8a250514fa2d34b30bc3c0dc37c65ff # v2.87.8 with: tool: cargo-audit@0.22.2 # `make audit` is a bare `cargo audit`: no ignore list, nothing @@ -84,7 +84,7 @@ jobs: - uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable with: components: clippy, rustfmt - - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 + - uses: Swatinem/rust-cache@f0d9c3887740aee45f6153b24b3a6b815192ec16 # v2 - name: Unit tests run: cargo test --workspace --all-features --locked # A taste of the nightly deterministic simulation @@ -524,8 +524,8 @@ jobs: with: persist-credentials: false - uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable - - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 - - uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0 + - uses: Swatinem/rust-cache@f0d9c3887740aee45f6153b24b3a6b815192ec16 # v2 + - uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 with: version: 0.12.6 - name: Sync dev dependencies @@ -616,9 +616,9 @@ jobs: if: steps.gate.outputs.enabled == 'true' - uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable if: steps.gate.outputs.enabled == 'true' - - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 + - uses: Swatinem/rust-cache@f0d9c3887740aee45f6153b24b3a6b815192ec16 # v2 if: steps.gate.outputs.enabled == 'true' - - uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0 + - uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 if: steps.gate.outputs.enabled == 'true' with: version: 0.12.6 @@ -638,7 +638,7 @@ jobs: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - - uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0 + - uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 with: version: 0.12.6 - name: Sync dev dependencies @@ -659,8 +659,8 @@ jobs: with: persist-credentials: false - uses: dtolnay/rust-toolchain@5b842231ba77f5c045dba54ac5560fed2db780e2 # nightly - - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 - - uses: taiki-e/install-action@6cd13508893c0e7eab5f273c2575d3859bd7229a # v2.86.6 + - uses: Swatinem/rust-cache@f0d9c3887740aee45f6153b24b3a6b815192ec16 # v2 + - uses: taiki-e/install-action@d438492cf8a250514fa2d34b30bc3c0dc37c65ff # v2.87.8 with: tool: cargo-fuzz@0.13.2 # Keep the fuzz targets compiling. Coverage-guided runs stay manual @@ -1059,7 +1059,7 @@ jobs: # the repo is private (it reactivates automatically once the repo is public). - name: Generate artifact attestation if: ${{ !github.event.repository.private }} - uses: actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373 # v4.1.1 + uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2 with: subject-path: 'dist/*' # Last gate before trusted publishing: the same check again, now covering @@ -1109,13 +1109,13 @@ jobs: with: toolchain: 1.98.1 targets: arm-unknown-linux-musleabihf - - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 + - uses: Swatinem/rust-cache@f0d9c3887740aee45f6153b24b3a6b815192ec16 # v2 with: key: armv6 # Kept in step with docker.yml: 0.23.0 filters the # `-Wl,--fix-cortex-a53-843419` that Rust 1.98 emits for aarch64-linux and # zig rejects (rust-cross/cargo-zigbuild#452). - - uses: taiki-e/install-action@6cd13508893c0e7eab5f273c2575d3859bd7229a # v2.86.6 + - uses: taiki-e/install-action@d438492cf8a250514fa2d34b30bc3c0dc37c65ff # v2.87.8 with: tool: cargo-zigbuild@0.23.0 # Pin+hash ziglang so a hijacked or yanked PyPI release can't poison the @@ -1209,7 +1209,7 @@ jobs: # the repo is private (it reactivates automatically once the repo is public). - name: Generate artifact attestation if: ${{ !github.event.repository.private }} - uses: actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373 # v4.1.1 + uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2 with: subject-path: 'binaries/pypiron-*' - name: Publish to GitHub Release diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml index 045e6e9..0d3fae5 100644 --- a/.github/workflows/docker.yml +++ b/.github/workflows/docker.yml @@ -159,14 +159,14 @@ jobs: with: toolchain: ${{ matrix.toolchain || 'stable' }} targets: ${{ matrix.triple }} - - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 + - uses: Swatinem/rust-cache@f0d9c3887740aee45f6153b24b3a6b815192ec16 # v2 with: key: docker-${{ matrix.id }} # 0.23.0 or newer: Rust 1.98 passes `-Wl,--fix-cortex-a53-843419` on every # aarch64-linux target (rust-lang/rust#155453) and zig's cc driver rejects # it, so the arm64 link died until cargo-zigbuild learned to filter the # flag (rust-cross/cargo-zigbuild#452, first released in 0.23.0). - - uses: taiki-e/install-action@6cd13508893c0e7eab5f273c2575d3859bd7229a # v2.86.6 + - uses: taiki-e/install-action@d438492cf8a250514fa2d34b30bc3c0dc37c65ff # v2.87.8 with: tool: cargo-zigbuild@0.23.0 @@ -205,7 +205,7 @@ jobs: with: images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} - - uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0 + - uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0 # Building needs no emulation (COPY only), but the smoke test RUNS the # image, so every non-amd64 arch gets QEMU binfmt. It boots the server, @@ -278,7 +278,7 @@ jobs: pattern: digest-* merge-multiple: true - - uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0 + - uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0 - name: Docker metadata (tags) id: meta @@ -324,7 +324,7 @@ jobs: # the repo is private (it reactivates automatically once the repo is public). - name: Attest provenance if: ${{ !github.event.repository.private }} - uses: actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373 # v4.1.1 + uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2 with: subject-name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} subject-digest: ${{ steps.manifest.outputs.digest }} diff --git a/.github/workflows/docs.yml b/.github/workflows/docs.yml index db58081..feefc6b 100644 --- a/.github/workflows/docs.yml +++ b/.github/workflows/docs.yml @@ -38,7 +38,7 @@ jobs: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - - uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0 + - uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 with: version: 0.12.6 - name: Build site @@ -61,4 +61,4 @@ jobs: url: ${{ steps.deployment.outputs.page_url }} steps: - id: deployment - uses: actions/deploy-pages@cd2ce8fcbc39b97be8ca5fce6e763baed58fa128 # v5.0.0 + uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 # v5.0.1 diff --git a/.github/workflows/fuzz.yml b/.github/workflows/fuzz.yml index 7d88296..1b35b7c 100644 --- a/.github/workflows/fuzz.yml +++ b/.github/workflows/fuzz.yml @@ -41,8 +41,8 @@ jobs: with: persist-credentials: false - uses: dtolnay/rust-toolchain@5b842231ba77f5c045dba54ac5560fed2db780e2 # nightly - - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 - - uses: taiki-e/install-action@6cd13508893c0e7eab5f273c2575d3859bd7229a # v2.86.6 + - uses: Swatinem/rust-cache@f0d9c3887740aee45f6153b24b3a6b815192ec16 # v2 + - uses: taiki-e/install-action@d438492cf8a250514fa2d34b30bc3c0dc37c65ff # v2.87.8 with: tool: cargo-fuzz@0.13.2 # Persist the growing corpus: a unique key always saves this run's corpus, diff --git a/.github/workflows/nightly-deps.yml b/.github/workflows/nightly-deps.yml index d27d30e..7a8f2cc 100644 --- a/.github/workflows/nightly-deps.yml +++ b/.github/workflows/nightly-deps.yml @@ -151,8 +151,8 @@ jobs: - uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable with: components: clippy, rustfmt # `make check` runs both; the action's default profile ships neither - - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 - - uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0 + - uses: Swatinem/rust-cache@f0d9c3887740aee45f6153b24b3a6b815192ec16 # v2 + - uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 - name: Bump inside the cooldown id: bump run: | @@ -430,8 +430,8 @@ jobs: - uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable with: components: clippy, rustfmt # `make check` runs both; the action's default profile ships neither - - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 - - uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0 + - uses: Swatinem/rust-cache@f0d9c3887740aee45f6153b24b3a6b815192ec16 # v2 + - uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 - name: The failed attempt's evidence uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: @@ -905,8 +905,8 @@ jobs: - uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable with: components: clippy, rustfmt # `make check` runs both; the action's default profile ships neither - - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 - - uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0 + - uses: Swatinem/rust-cache@f0d9c3887740aee45f6153b24b3a6b815192ec16 # v2 + - uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 - name: Record the base commit run: | set -euo pipefail diff --git a/.github/workflows/security.yaml b/.github/workflows/security.yaml index 6956320..fb87242 100644 --- a/.github/workflows/security.yaml +++ b/.github/workflows/security.yaml @@ -101,7 +101,7 @@ jobs: with: fetch-depth: 0 persist-credentials: false - - uses: trufflesecurity/trufflehog@6f3c981e7b77f235fd2702dd74af25fc4b72bf11 # v3.96.0 + - uses: trufflesecurity/trufflehog@363923b901c911a9164f50b6c423f47c15372b1c # v3.97.4 with: # The action defaults `version:` to `latest`, which means the engine # this job runs changes under it with no commit here. Pin it: a scanner @@ -149,7 +149,7 @@ jobs: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - - uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0 + - uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 with: version: 0.12.6 enable-cache: false @@ -175,7 +175,7 @@ jobs: with: persist-credentials: false - name: Scan lockfiles - uses: google/osv-scanner-action/osv-scanner-action@9a498708959aeaef5ef730655706c5a1df1edbc2 # v2.3.8 + uses: google/osv-scanner-action/osv-scanner-action@6e4298ebc4db23e847df9b2e2de2939d6f066c67 # v2.5.1 with: # Cargo.lock, fuzz/Cargo.lock, and uv.lock. v2 dropped --skip-git and # already excludes .git by default. @@ -235,7 +235,7 @@ jobs: # scan itself still runs and still gates via `exit-code: 1`. - name: Upload Trivy SARIF if: ${{ always() && !github.event.repository.private && hashFiles('trivy.sarif') != '' && (github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository) }} - uses: github/codeql-action/upload-sarif@f205ea1c3313d32999d8d6a48b4f6530d4437b38 # v4.37.4 + uses: github/codeql-action/upload-sarif@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 with: sarif_file: trivy.sarif category: trivy @@ -268,7 +268,7 @@ jobs: with: persist-credentials: false - name: Initialize CodeQL - uses: github/codeql-action/init@f205ea1c3313d32999d8d6a48b4f6530d4437b38 # v4.37.4 + uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 with: languages: ${{ matrix.language }} # security-extended catches more of what commercial SAST reports. @@ -278,9 +278,9 @@ jobs: # Excludes tests/ — harness noise, not shipped code. See the file. config-file: ./.github/codeql/codeql-config.yml - name: Autobuild - uses: github/codeql-action/autobuild@f205ea1c3313d32999d8d6a48b4f6530d4437b38 # v4.37.4 + uses: github/codeql-action/autobuild@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 - name: Analyze - uses: github/codeql-action/analyze@f205ea1c3313d32999d8d6a48b4f6530d4437b38 # v4.37.4 + uses: github/codeql-action/analyze@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 with: category: '/language:${{ matrix.language }}' @@ -365,7 +365,7 @@ jobs: # Fork PRs skip the upload — read-only token, see the Trivy note above. - name: Upload Semgrep SARIF if: ${{ always() && !github.event.repository.private && hashFiles('semgrep.sarif') != '' && (github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository) }} - uses: github/codeql-action/upload-sarif@f205ea1c3313d32999d8d6a48b4f6530d4437b38 # v4.37.4 + uses: github/codeql-action/upload-sarif@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 with: sarif_file: semgrep.sarif category: semgrep @@ -381,7 +381,7 @@ jobs: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - - uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0 + - uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 with: version: 0.12.6 enable-cache: false @@ -509,7 +509,7 @@ jobs: # this job's rights should change only when this line does. Leading # `v` required: the action builds the download URL from it verbatim. snyk-version: v1.1307.0 - - uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0 + - uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 if: env.SNYK_CONFIGURED == 'true' with: version: 0.12.6 @@ -595,13 +595,13 @@ jobs: # security events. The scans above still gate in both cases. - name: Upload Snyk OSS SARIF if: ${{ always() && env.SNYK_CONFIGURED == 'true' && !github.event.repository.private && hashFiles('snyk-oss.sarif') != '' && (github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository) }} - uses: github/codeql-action/upload-sarif@f205ea1c3313d32999d8d6a48b4f6530d4437b38 # v4.37.4 + uses: github/codeql-action/upload-sarif@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 with: sarif_file: snyk-oss.sarif category: snyk-oss - name: Upload Snyk Code SARIF if: ${{ always() && env.SNYK_CONFIGURED == 'true' && !github.event.repository.private && hashFiles('snyk-code.sarif') != '' && (github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository) }} - uses: github/codeql-action/upload-sarif@f205ea1c3313d32999d8d6a48b4f6530d4437b38 # v4.37.4 + uses: github/codeql-action/upload-sarif@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 with: sarif_file: snyk-code.sarif category: snyk-code diff --git a/.github/workflows/selfcheck.yml b/.github/workflows/selfcheck.yml index 2d9d475..cff0502 100644 --- a/.github/workflows/selfcheck.yml +++ b/.github/workflows/selfcheck.yml @@ -120,7 +120,7 @@ jobs: - name: AWS OIDC — assume the soak role if: env.HAS_SOAK_AWS_ROLE == 'true' - uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3 + uses: aws-actions/configure-aws-credentials@cbe3b392738ccf3f987d68400dafcf4b0624a56c # v6.2.4 with: role-to-assume: ${{ vars.SOAK_AWS_ROLE }} aws-region: ${{ vars.SOAK_AWS_REGION || 'us-east-1' }} diff --git a/.github/workflows/simulation.yml b/.github/workflows/simulation.yml index 9e32bff..ce523f8 100644 --- a/.github/workflows/simulation.yml +++ b/.github/workflows/simulation.yml @@ -119,7 +119,7 @@ jobs: with: persist-credentials: false - uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable - - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 + - uses: Swatinem/rust-cache@f0d9c3887740aee45f6153b24b3a6b815192ec16 # v2 # Seeds rotate nightly (day number scales the start), so every night # explores fresh schedules while any night's failure still reproduces # from its printed seed. @@ -337,7 +337,7 @@ jobs: with: persist-credentials: false - uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable - - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 + - uses: Swatinem/rust-cache@f0d9c3887740aee45f6153b24b3a6b815192ec16 # v2 # `--max-secs` instead of `--seeds`, because this lane's output is a RATE, # not a verdict: without it the run stops at its first failing seed (~300 # seeds in) and reports nothing you can watch trend. It also bounds the @@ -388,7 +388,7 @@ jobs: with: persist-credentials: false - uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable - - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 + - uses: Swatinem/rust-cache@f0d9c3887740aee45f6153b24b3a6b815192ec16 # v2 # Seeds stride by day like the VOPR rows: every night explores fresh # schedules, and any night's failure still reproduces from its printed # seed alone. 5M seeds is ~10 minutes on a runner, and the timeout above @@ -427,7 +427,7 @@ jobs: with: persist-credentials: false - uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable - - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 + - uses: Swatinem/rust-cache@f0d9c3887740aee45f6153b24b3a6b815192ec16 # v2 - name: Exhaustively check the deep model configurations run: | cargo test --release --test model_replication --test model_event_protocol \ diff --git a/.github/workflows/soak-bundle.yml b/.github/workflows/soak-bundle.yml index f5bd33f..6588d30 100644 --- a/.github/workflows/soak-bundle.yml +++ b/.github/workflows/soak-bundle.yml @@ -67,7 +67,7 @@ jobs: dev/ops/soak/pypiron-soak@.service dev/ops/soak/pypiron-soak-reporter.service \ dev/ops/soak/pypiron-soak-refresh.service dev/ops/soak/pypiron-soak-refresh.timer stage/ tar czf bundle.tar.gz -C stage . - - uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3 + - uses: aws-actions/configure-aws-credentials@cbe3b392738ccf3f987d68400dafcf4b0624a56c # v6.2.4 with: role-to-assume: ${{ vars.SOAK_AWS_ROLE }} aws-region: ${{ vars.SOAK_AWS_REGION || 'us-east-1' }} diff --git a/.github/workflows/weekly.yml b/.github/workflows/weekly.yml index 57b4a0f..ad845d9 100644 --- a/.github/workflows/weekly.yml +++ b/.github/workflows/weekly.yml @@ -29,8 +29,8 @@ jobs: with: persist-credentials: false - uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable - - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 - - uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0 + - uses: Swatinem/rust-cache@f0d9c3887740aee45f6153b24b3a6b815192ec16 # v2 + - uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 with: version: 0.12.6 - name: Sync dev dependencies @@ -49,7 +49,7 @@ jobs: with: persist-credentials: false - uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable - - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 + - uses: Swatinem/rust-cache@f0d9c3887740aee45f6153b24b3a6b815192ec16 # v2 # #[ignore]d test: parses real file metadata for the whole PyPI corpus # (17M rows). The ClickHouse playground caps demo queries at 100k result # rows, so CI uses a pinned snapshot published as a release asset. To @@ -80,8 +80,8 @@ jobs: - uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable with: components: llvm-tools-preview - - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 - - uses: taiki-e/install-action@6cd13508893c0e7eab5f273c2575d3859bd7229a # v2.86.6 + - uses: Swatinem/rust-cache@f0d9c3887740aee45f6153b24b3a6b815192ec16 # v2 + - uses: taiki-e/install-action@d438492cf8a250514fa2d34b30bc3c0dc37c65ff # v2.87.8 with: tool: cargo-llvm-cov@0.9.0 # `make -s` prints only the summary table (stdout); build noise goes to @@ -150,9 +150,9 @@ jobs: persist-credentials: false - uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable if: steps.gate.outputs.enabled == 'true' - - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 + - uses: Swatinem/rust-cache@f0d9c3887740aee45f6153b24b3a6b815192ec16 # v2 if: steps.gate.outputs.enabled == 'true' - - uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0 + - uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 if: steps.gate.outputs.enabled == 'true' with: version: 0.12.6