Skip to content

Commit 5a48f7f

Browse files
authored
Merge pull request #712 from openai/codex/pin-github-workflow-refs-20260326-184341
[codex] Pin GitHub Actions workflow references
2 parents ae574a3 + 3349f80 commit 5a48f7f

5 files changed

Lines changed: 25 additions & 25 deletions

File tree

.github/workflows/ci.yml

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -22,10 +22,10 @@ jobs:
2222
if: (github.event_name == 'push' || github.event.pull_request.head.repo.fork) && (github.event_name != 'push' || github.event.head_commit.message != 'codegen metadata')
2323

2424
steps:
25-
- uses: actions/checkout@v6
25+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
2626

2727
- name: Set up Java
28-
uses: actions/setup-java@v5
28+
uses: actions/setup-java@be666c2fcd27ec809703dec50e508c2fdc7f6654 # v5
2929
with:
3030
distribution: temurin
3131
java-version: |
@@ -34,7 +34,7 @@ jobs:
3434
cache: gradle
3535

3636
- name: Set up Gradle
37-
uses: gradle/actions/setup-gradle@v4
37+
uses: gradle/actions/setup-gradle@0b6dd653ba04f4f93bf581ec31e66cbd7dcb644d # v4
3838

3939
- name: Run lints
4040
run: ./scripts/lint
@@ -49,10 +49,10 @@ jobs:
4949
if: (github.event_name == 'push' || github.event.pull_request.head.repo.fork) && (github.event_name != 'push' || github.event.head_commit.message != 'codegen metadata')
5050

5151
steps:
52-
- uses: actions/checkout@v6
52+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
5353

5454
- name: Set up Java
55-
uses: actions/setup-java@v5
55+
uses: actions/setup-java@be666c2fcd27ec809703dec50e508c2fdc7f6654 # v5
5656
with:
5757
distribution: temurin
5858
java-version: |
@@ -61,7 +61,7 @@ jobs:
6161
cache: gradle
6262

6363
- name: Set up Gradle
64-
uses: gradle/actions/setup-gradle@v4
64+
uses: gradle/actions/setup-gradle@0b6dd653ba04f4f93bf581ec31e66cbd7dcb644d # v4
6565

6666
- name: Build SDK
6767
# disable gradle daemon in CI because it is flakey
@@ -120,10 +120,10 @@ jobs:
120120
runs-on: ${{ github.repository == 'stainless-sdks/openai-java' && 'depot-ubuntu-24.04' || 'ubuntu-latest' }}
121121
if: github.event_name == 'push' || github.event.pull_request.head.repo.fork
122122
steps:
123-
- uses: actions/checkout@v6
123+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
124124

125125
- name: Set up Java
126-
uses: actions/setup-java@v5
126+
uses: actions/setup-java@be666c2fcd27ec809703dec50e508c2fdc7f6654 # v5
127127
with:
128128
distribution: temurin
129129
java-version: |
@@ -132,7 +132,7 @@ jobs:
132132
cache: gradle
133133

134134
- name: Set up Gradle
135-
uses: gradle/gradle-build-action@v2
135+
uses: gradle/gradle-build-action@fe583dc97e032f41ccc310ea5176f2d7306abbc4 # v2
136136

137137
- name: Run tests
138138
run: ./scripts/test
@@ -143,18 +143,18 @@ jobs:
143143
if: github.repository == 'openai/openai-java' && (github.event_name == 'push' || github.event.pull_request.head.repo.fork) && (github.event_name != 'push' || github.event.head_commit.message != 'codegen metadata')
144144

145145
steps:
146-
- uses: actions/checkout@v6
146+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
147147

148148
- name: Set up Java
149-
uses: actions/setup-java@v5
149+
uses: actions/setup-java@be666c2fcd27ec809703dec50e508c2fdc7f6654 # v5
150150
with:
151151
distribution: temurin
152152
java-version: |
153153
8
154154
21
155155
cache: gradle
156156
- name: Set up Gradle
157-
uses: gradle/gradle-build-action@v2
157+
uses: gradle/gradle-build-action@fe583dc97e032f41ccc310ea5176f2d7306abbc4 # v2
158158

159159
- env:
160160
OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }}

.github/workflows/create-releases.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -14,17 +14,17 @@ jobs:
1414
environment: publish
1515

1616
steps:
17-
- uses: actions/checkout@v6
17+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
1818

19-
- uses: stainless-api/trigger-release-please@v1
19+
- uses: stainless-api/trigger-release-please@bb6677c5a04578eec1ccfd9e1913b5b78ed64c61 # v1
2020
id: release
2121
with:
2222
repo: ${{ github.event.repository.full_name }}
2323
stainless-api-key: ${{ secrets.STAINLESS_API_KEY }}
2424

2525
- name: Set up Java
2626
if: ${{ steps.release.outputs.releases_created }}
27-
uses: actions/setup-java@v5
27+
uses: actions/setup-java@be666c2fcd27ec809703dec50e508c2fdc7f6654 # v5
2828
with:
2929
distribution: temurin
3030
java-version: |
@@ -34,7 +34,7 @@ jobs:
3434

3535
- name: Set up Gradle
3636
if: ${{ steps.release.outputs.releases_created }}
37-
uses: gradle/gradle-build-action@v2
37+
uses: gradle/gradle-build-action@fe583dc97e032f41ccc310ea5176f2d7306abbc4 # v2
3838

3939
- name: Compile the openai-java-core project
4040
run: |
@@ -45,7 +45,7 @@ jobs:
4545
./scripts/mock --daemon
4646
4747
- name: Setup GraalVM
48-
uses: graalvm/setup-graalvm@v1
48+
uses: graalvm/setup-graalvm@03e8abf916fd0e281b2efe7b2da3378bb0a1d085 # v1
4949
with:
5050
java-version: 21
5151
distribution: 'graalvm-community'

.github/workflows/detect-breaking-changes.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -15,21 +15,21 @@ jobs:
1515
run: |
1616
echo "FETCH_DEPTH=$(expr ${{ github.event.pull_request.commits }} + 1)" >> $GITHUB_ENV
1717
18-
- uses: actions/checkout@v6
18+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
1919
with:
2020
# Ensure we can check out the pull request base in the script below.
2121
fetch-depth: ${{ env.FETCH_DEPTH }}
2222

2323
- name: Set up Java
24-
uses: actions/setup-java@v5
24+
uses: actions/setup-java@be666c2fcd27ec809703dec50e508c2fdc7f6654 # v5
2525
with:
2626
distribution: temurin
2727
java-version: |
2828
8
2929
21
3030
cache: gradle
3131
- name: Set up Gradle
32-
uses: gradle/gradle-build-action@v2
32+
uses: gradle/gradle-build-action@fe583dc97e032f41ccc310ea5176f2d7306abbc4 # v2
3333

3434
- name: Detect breaking changes
3535
run: |

.github/workflows/publish-sonatype.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -10,10 +10,10 @@ jobs:
1010
runs-on: ubuntu-latest
1111

1212
steps:
13-
- uses: actions/checkout@v6
13+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
1414

1515
- name: Set up Java
16-
uses: actions/setup-java@v5
16+
uses: actions/setup-java@be666c2fcd27ec809703dec50e508c2fdc7f6654 # v5
1717
with:
1818
distribution: temurin
1919
java-version: |
@@ -22,7 +22,7 @@ jobs:
2222
cache: gradle
2323

2424
- name: Set up Gradle
25-
uses: gradle/gradle-build-action@v2
25+
uses: gradle/gradle-build-action@fe583dc97e032f41ccc310ea5176f2d7306abbc4 # v2
2626

2727
- name: Compile the openai-java-core project
2828
run: |
@@ -33,7 +33,7 @@ jobs:
3333
./scripts/mock --daemon
3434
3535
- name: Setup GraalVM
36-
uses: graalvm/setup-graalvm@v1
36+
uses: graalvm/setup-graalvm@03e8abf916fd0e281b2efe7b2da3378bb0a1d085 # v1
3737
with:
3838
java-version: 21
3939
distribution: 'graalvm-community'

.github/workflows/release-doctor.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ jobs:
1313
if: github.repository == 'openai/openai-java' && (github.event_name == 'push' || github.event_name == 'workflow_dispatch' || startsWith(github.head_ref, 'release-please') || github.head_ref == 'next')
1414

1515
steps:
16-
- uses: actions/checkout@v6
16+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
1717

1818
- name: Check release environment
1919
run: |

0 commit comments

Comments
 (0)