From f798a2ae4967654a30779d3227445eb4fcd54d08 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 1 Jul 2026 22:58:03 +0000 Subject: [PATCH] chore(deps): bump the github-actions-all group with 15 updates Bumps the github-actions-all group with 15 updates: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `6.0.2` | `7.0.0` | | [mozilla-actions/sccache-action](https://github.com/mozilla-actions/sccache-action) | `0.0.9` | `0.0.10` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `7.0.0` | `7.0.1` | | [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `2.5.0` | `3.0.1` | | [actions/cache/restore](https://github.com/actions/cache) | `5.0.3` | `6.1.0` | | [actions/cache/save](https://github.com/actions/cache) | `5.0.3` | `6.1.0` | | [marocchino/sticky-pull-request-comment](https://github.com/marocchino/sticky-pull-request-comment) | `3.0.2` | `3.0.4` | | [actions/setup-python](https://github.com/actions/setup-python) | `6.2.0` | `6.3.0` | | [actions/create-github-app-token](https://github.com/actions/create-github-app-token) | `2.2.1` | `3.2.0` | | [actions/github-script](https://github.com/actions/github-script) | `8` | `9` | | [DavidAnson/markdownlint-cli2-action](https://github.com/davidanson/markdownlint-cli2-action) | `22.0.0` | `23.2.0` | | [crate-ci/typos](https://github.com/crate-ci/typos) | `1.44.0` | `1.47.2` | | [pnpm/action-setup](https://github.com/pnpm/action-setup) | `5.0.0` | `6.0.9` | | [actions/stale](https://github.com/actions/stale) | `10.2.0` | `10.3.0` | | [peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request) | `8.1.0` | `8.1.1` | Updates `actions/checkout` from 6.0.2 to 7.0.0 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67214ff5f5447ce83dd...9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0) Updates `mozilla-actions/sccache-action` from 0.0.9 to 0.0.10 - [Release notes](https://github.com/mozilla-actions/sccache-action/releases) - [Commits](https://github.com/mozilla-actions/sccache-action/compare/7d986dd989559c6ecdb630a3fd2557667be217ad...9e7fa8a12102821edf02ca5dbea1acd0f89a2696) Updates `actions/upload-artifact` from 7.0.0 to 7.0.1 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](https://github.com/actions/upload-artifact/compare/bbbca2ddaa5d8feaa63e36b76fdaad77386f024f...043fb46d1a93c77aae656e7c1c64a875d1fc6a0a) Updates `softprops/action-gh-release` from 2.5.0 to 3.0.1 - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](https://github.com/softprops/action-gh-release/compare/a06a81a03ee405af7f2048a818ed3f03bbf83c7b...718ea10b132b3b2eba29c1007bb80653f286566b) Updates `actions/cache/restore` from 5.0.3 to 6.1.0 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](https://github.com/actions/cache/compare/cdf6c1fa76f9f475f3d7449005a359c84ca0f306...55cc8345863c7cc4c66a329aec7e433d2d1c52a9) Updates `actions/cache/save` from 5.0.3 to 6.1.0 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](https://github.com/actions/cache/compare/cdf6c1fa76f9f475f3d7449005a359c84ca0f306...55cc8345863c7cc4c66a329aec7e433d2d1c52a9) Updates `marocchino/sticky-pull-request-comment` from 3.0.2 to 3.0.4 - [Release notes](https://github.com/marocchino/sticky-pull-request-comment/releases) - [Commits](https://github.com/marocchino/sticky-pull-request-comment/compare/70d2764d1a7d5d9560b100cbea0077fc8f633987...0ea0beb66eb9baf113663a64ec522f60e49231c0) Updates `actions/setup-python` from 6.2.0 to 6.3.0 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](https://github.com/actions/setup-python/compare/a309ff8b426b58ec0e2a45f0f869d46889d02405...ece7cb06caefa5fff74198d8649806c4678c61a1) Updates `actions/create-github-app-token` from 2.2.1 to 3.2.0 - [Release notes](https://github.com/actions/create-github-app-token/releases) - [Changelog](https://github.com/actions/create-github-app-token/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/create-github-app-token/compare/29824e69f54612133e76f7eaac726eef6c875baf...bcd2ba49218906704ab6c1aa796996da409d3eb1) Updates `actions/github-script` from 8 to 9 - [Release notes](https://github.com/actions/github-script/releases) - [Commits](https://github.com/actions/github-script/compare/v8...v9) Updates `DavidAnson/markdownlint-cli2-action` from 22.0.0 to 23.2.0 - [Release notes](https://github.com/davidanson/markdownlint-cli2-action/releases) - [Commits](https://github.com/davidanson/markdownlint-cli2-action/compare/07035fd053f7be764496c0f8d8f9f41f98305101...ded1f9488f68a970bc66ea5619e13e9b52e601cd) Updates `crate-ci/typos` from 1.44.0 to 1.47.2 - [Release notes](https://github.com/crate-ci/typos/releases) - [Changelog](https://github.com/crate-ci/typos/blob/master/CHANGELOG.md) - [Commits](https://github.com/crate-ci/typos/compare/631208b7aac2daa8b707f55e7331f9112b0e062d...37bb98842b0d8c4ffebdb75301a13db0267cef89) Updates `pnpm/action-setup` from 5.0.0 to 6.0.9 - [Release notes](https://github.com/pnpm/action-setup/releases) - [Commits](https://github.com/pnpm/action-setup/compare/fc06bc1257f339d1d5d8b3a19a8cae5388b55320...0ebf47130e4866e96fce0953f49152a61190b271) Updates `actions/stale` from 10.2.0 to 10.3.0 - [Release notes](https://github.com/actions/stale/releases) - [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/stale/compare/b5d41d4e1d5dceea10e7104786b73624c18a190f...eb5cf3af3ac0a1aa4c9c45633dd1ae542a27a899) Updates `peter-evans/create-pull-request` from 8.1.0 to 8.1.1 - [Release notes](https://github.com/peter-evans/create-pull-request/releases) - [Commits](https://github.com/peter-evans/create-pull-request/compare/c0f553fe549906ede9cf27b5156039d195d2ece0...5f6978faf089d4d20b00c7766989d076bb2fc7f1) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions-all - dependency-name: mozilla-actions/sccache-action dependency-version: 0.0.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions-all - dependency-name: actions/upload-artifact dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions-all - dependency-name: softprops/action-gh-release dependency-version: 3.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions-all - dependency-name: actions/cache/restore dependency-version: 6.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions-all - dependency-name: actions/cache/save dependency-version: 6.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions-all - dependency-name: marocchino/sticky-pull-request-comment dependency-version: 3.0.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions-all - dependency-name: actions/setup-python dependency-version: 6.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-all - dependency-name: actions/create-github-app-token dependency-version: 3.2.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions-all - dependency-name: actions/github-script dependency-version: '9' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions-all - dependency-name: DavidAnson/markdownlint-cli2-action dependency-version: 23.2.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions-all - dependency-name: crate-ci/typos dependency-version: 1.47.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-all - dependency-name: pnpm/action-setup dependency-version: 6.0.9 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions-all - dependency-name: actions/stale dependency-version: 10.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-all - dependency-name: peter-evans/create-pull-request dependency-version: 8.1.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions-all ... Signed-off-by: dependabot[bot] --- .../workflows/attach-binaries-to-release.yml | 8 ++-- .github/workflows/code.yml | 46 +++++++++---------- .github/workflows/create-release-announce.yml | 8 ++-- ...create-tx-for-multisig-node-governance.yml | 4 +- .../create-tx-for-multisig-subsidy.yml | 4 +- .../workflows/gen-sui-upgrade-version-pr.yml | 4 +- .github/workflows/issues-monitor.yaml | 2 +- .github/workflows/lint.yml | 22 ++++----- .github/workflows/notify-walrus-sites.yml | 4 +- .github/workflows/pages-preview.yaml | 12 ++--- .github/workflows/publish-docs.yaml | 8 ++-- .github/workflows/release-notes.yml | 10 ++-- .github/workflows/sccache-warmup.yml | 4 +- .github/workflows/stale-prs.yaml | 2 +- .github/workflows/tag.yml | 2 +- .github/workflows/update-operators-cache.yml | 4 +- .github/workflows/update-ws-binaries.yaml | 2 +- .github/workflows/update-ws-install.yaml | 2 +- .github/workflows/version-bump.yml | 4 +- 19 files changed, 76 insertions(+), 76 deletions(-) diff --git a/.github/workflows/attach-binaries-to-release.yml b/.github/workflows/attach-binaries-to-release.yml index 6d835de483..a97f963ddc 100644 --- a/.github/workflows/attach-binaries-to-release.yml +++ b/.github/workflows/attach-binaries-to-release.yml @@ -91,7 +91,7 @@ jobs: echo "walrus_version=${walrus_version}" >> $GITHUB_ENV - name: Check out ${{ env.walrus_tag }} - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 with: ref: ${{ env.walrus_tag }} @@ -236,7 +236,7 @@ jobs: - name: Setup sccache if: ${{ !startsWith(matrix.os, 'ubuntu') && env.gcp_existing_archive == '' }} - uses: mozilla-actions/sccache-action@7d986dd989559c6ecdb630a3fd2557667be217ad # pin@v0.0.9 + uses: mozilla-actions/sccache-action@9e7fa8a12102821edf02ca5dbea1acd0f89a2696 # pin@v0.0.10 - name: Cargo build for ${{ matrix.os }} platform if: ${{ !startsWith(matrix.os, 'ubuntu') && env.gcp_existing_archive == '' }} @@ -274,7 +274,7 @@ jobs: parent: false - name: Upload release artifacts for ${{ matrix.os }} platform - uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # pin@7.0.0 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # pin@7.0.1 with: name: walrus-binaries-${{ matrix.os }} if-no-files-found: error @@ -282,7 +282,7 @@ jobs: ./tmp/walrus-${{ env.walrus_tag }}-${{ env.os_type }}.tgz - name: Attach artifacts to ${{ env.walrus_tag }} release in GH - uses: softprops/action-gh-release@a06a81a03ee405af7f2048a818ed3f03bbf83c7b # pin@v2.5.0 + uses: softprops/action-gh-release@718ea10b132b3b2eba29c1007bb80653f286566b # pin@v3.0.1 with: tag_name: ${{ env.walrus_tag }} files: | diff --git a/.github/workflows/code.yml b/.github/workflows/code.yml index adf2000704..a521491300 100644 --- a/.github/workflows/code.yml +++ b/.github/workflows/code.yml @@ -45,7 +45,7 @@ jobs: isExampleConfig: ${{ steps.diff.outputs.isExampleConfig }} isCLI: ${{ steps.diff.outputs.isCLI }} steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 - name: Detect Changes uses: "./.github/actions/diffs" id: diff @@ -56,7 +56,7 @@ jobs: if: ${{ needs.diff.outputs.isRust == 'true' || needs.diff.outputs.isDenyConfig == 'true' }} runs-on: ubuntu-latest steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 - uses: taiki-e/install-action@a2352fc6ce487f030a3aa709482d57823eadfb37 # pin@v2.75.16 with: tool: cargo-deny@0.18.4 @@ -69,7 +69,7 @@ jobs: if: ${{ needs.diff.outputs.isRust == 'true' }} runs-on: ubuntu-ghcloud steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 - uses: ./.github/actions/sccache with: gcp_credentials_json: ${{ secrets.GCP_WALRUS_RELEASE_BUCKET_SVCUSER_CREDENTIALS }} @@ -94,7 +94,7 @@ jobs: OPENSSL_NO_VENDOR: "0" runs-on: ubuntu-ghcloud steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 - uses: ./.github/actions/sccache with: gcp_credentials_json: ${{ secrets.GCP_WALRUS_RELEASE_BUCKET_SVCUSER_CREDENTIALS }} @@ -122,7 +122,7 @@ jobs: - uses: taiki-e/install-action@a2352fc6ce487f030a3aa709482d57823eadfb37 # pin@v2.75.16 with: tool: cargo-nextest - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 - uses: ./.github/actions/sccache with: gcp_credentials_json: ${{ secrets.GCP_WALRUS_RELEASE_BUCKET_SVCUSER_CREDENTIALS }} @@ -166,7 +166,7 @@ jobs: - uses: taiki-e/install-action@a2352fc6ce487f030a3aa709482d57823eadfb37 # pin@v2.75.16 with: tool: cargo-nextest - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 - uses: ./.github/actions/sccache with: gcp_credentials_json: ${{ secrets.GCP_WALRUS_RELEASE_BUCKET_SVCUSER_CREDENTIALS }} @@ -193,7 +193,7 @@ jobs: - uses: taiki-e/install-action@a2352fc6ce487f030a3aa709482d57823eadfb37 # pin@v2.75.16 with: tool: cargo-nextest - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 - uses: ./.github/actions/sccache with: gcp_credentials_json: ${{ secrets.GCP_WALRUS_RELEASE_BUCKET_SVCUSER_CREDENTIALS }} @@ -223,7 +223,7 @@ jobs: - uses: taiki-e/install-action@a2352fc6ce487f030a3aa709482d57823eadfb37 # pin@v2.75.16 with: tool: cargo-nextest - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 - run: ./scripts/simtest/install.sh - name: Build simtests run: cargo simtest build @@ -236,7 +236,7 @@ jobs: env: SUI_BIN: "/home/runner/.cargo/bin/sui" steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 - name: Get Sui tag shell: bash @@ -247,7 +247,7 @@ jobs: - name: Restore cached sui binary id: cache-sui-restore - uses: actions/cache/restore@cdf6c1fa76f9f475f3d7449005a359c84ca0f306 # pin@v5.0.3 + uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # pin@v6.1.0 with: path: ${{ env.SUI_BIN }} key: ${{ runner.os }}-${{ runner.arch }}-${{ env.SUI_TAG }} @@ -266,7 +266,7 @@ jobs: run: bash ./scripts/move_tests.sh - name: Cache sui binary if: ${{ github.ref == 'refs/heads/main' && steps.cache-sui-restore.outputs.cache-hit != 'true' }} - uses: actions/cache/save@cdf6c1fa76f9f475f3d7449005a359c84ca0f306 # pin@v5.0.3 + uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # pin@v6.1.0 with: path: ${{ env.SUI_BIN }} key: ${{ steps.cache-sui-restore.outputs.cache-primary-key }} @@ -281,7 +281,7 @@ jobs: env: SUI_BIN: "/home/runner/.cargo/bin/sui" steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 - name: Get Sui tag shell: bash @@ -292,7 +292,7 @@ jobs: - name: Restore cached sui binary id: cache-sui-restore - uses: actions/cache/restore@cdf6c1fa76f9f475f3d7449005a359c84ca0f306 # pin@v5.0.3 + uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # pin@v6.1.0 with: path: ${{ env.SUI_BIN }} key: ${{ runner.os }}-${{ runner.arch }}-${{ env.SUI_TAG }} @@ -317,9 +317,9 @@ jobs: contents: read pull-requests: write steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 - name: Post a warning if the PR touches the testnet-contracts directory - uses: marocchino/sticky-pull-request-comment@70d2764d1a7d5d9560b100cbea0077fc8f633987 # pin@v3.0.2 + uses: marocchino/sticky-pull-request-comment@0ea0beb66eb9baf113663a64ec522f60e49231c0 # pin@v3.0.4 with: message: > **Warning:** This PR touches the `testnet-contracts` directory. This should only be @@ -335,9 +335,9 @@ jobs: contents: read pull-requests: write steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 - name: Post a warning if the PR touches the mainnet-contracts directory - uses: marocchino/sticky-pull-request-comment@70d2764d1a7d5d9560b100cbea0077fc8f633987 # pin@v3.0.2 + uses: marocchino/sticky-pull-request-comment@0ea0beb66eb9baf113663a64ec522f60e49231c0 # pin@v3.0.4 with: message: > **Warning:** This PR touches the `mainnet-contracts` directory. This should only be @@ -352,9 +352,9 @@ jobs: contents: read pull-requests: write steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 - name: Post a warning if the PR touches an example config file - uses: marocchino/sticky-pull-request-comment@70d2764d1a7d5d9560b100cbea0077fc8f633987 # pin@v3.0.2 + uses: marocchino/sticky-pull-request-comment@0ea0beb66eb9baf113663a64ec522f60e49231c0 # pin@v3.0.4 with: message: | **Warning:** This PR modifies one of the example config files. Please consider the @@ -378,9 +378,9 @@ jobs: contents: read pull-requests: write steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 - name: Post a warning if the PR modifies the Walrus CLI - uses: marocchino/sticky-pull-request-comment@70d2764d1a7d5d9560b100cbea0077fc8f633987 # pin@v3.0.2 + uses: marocchino/sticky-pull-request-comment@0ea0beb66eb9baf113663a64ec522f60e49231c0 # pin@v3.0.4 with: message: | **Warning:** This PR modifies the Walrus CLI. Please consider the following: @@ -402,9 +402,9 @@ jobs: contents: read pull-requests: write steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 - name: Post a warning if the PR touches an OpenAPI file - uses: marocchino/sticky-pull-request-comment@70d2764d1a7d5d9560b100cbea0077fc8f633987 # pin@v3.0.2 + uses: marocchino/sticky-pull-request-comment@0ea0beb66eb9baf113663a64ec522f60e49231c0 # pin@v3.0.4 with: message: | **Warning:** This PR modifies one of the OpenAPI files. Please consider the diff --git a/.github/workflows/create-release-announce.yml b/.github/workflows/create-release-announce.yml index 782615d29d..b43274d62f 100644 --- a/.github/workflows/create-release-announce.yml +++ b/.github/workflows/create-release-announce.yml @@ -38,7 +38,7 @@ jobs: steps: - name: Checkout walrus main branch - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 with: fetch-depth: 0 ref: main @@ -63,7 +63,7 @@ jobs: echo "previous_release_branch=${previous_release_branch}" >> $GITHUB_ENV - name: Checkout commit - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 with: fetch-depth: 0 ref: ${{ inputs.walrus_commit }} @@ -134,13 +134,13 @@ jobs: https://api.github.com/repos/MystenLabs/walrus/commits/${{ env.CURRENT_BRANCH }} | jq .sha | tr -d '"')" >> $GITHUB_ENV - name: Checkout main - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 with: fetch-depth: 0 ref: main - name: Setup Python - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # pin@v6.2.0 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # pin@v6.3.0 with: python-version: 3.10.10 diff --git a/.github/workflows/create-tx-for-multisig-node-governance.yml b/.github/workflows/create-tx-for-multisig-node-governance.yml index 56b88dcdfa..354bf90940 100644 --- a/.github/workflows/create-tx-for-multisig-node-governance.yml +++ b/.github/workflows/create-tx-for-multisig-node-governance.yml @@ -44,7 +44,7 @@ jobs: runs-on: ubuntu-latest steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 with: fetch-depth: 1 ref: ${{ inputs.commit }} @@ -78,7 +78,7 @@ jobs: cat artifacts/tx-data.txt - name: Upload Transaction Artifact - uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # pin@v7.0.0 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # pin@v7.0.1 with: name: transaction-data path: artifacts/tx-data.txt diff --git a/.github/workflows/create-tx-for-multisig-subsidy.yml b/.github/workflows/create-tx-for-multisig-subsidy.yml index 89804556ca..77fdd66a34 100644 --- a/.github/workflows/create-tx-for-multisig-subsidy.yml +++ b/.github/workflows/create-tx-for-multisig-subsidy.yml @@ -50,7 +50,7 @@ jobs: run: | echo ${{ inputs.transaction_type }} - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 with: fetch-depth: 1 ref: ${{ inputs.commit }} @@ -85,7 +85,7 @@ jobs: cat artifacts/tx-data.txt - name: Upload Transaction Artifact - uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # pin@v7.0.0 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # pin@v7.0.1 with: name: transaction-data path: artifacts/tx-data.txt diff --git a/.github/workflows/gen-sui-upgrade-version-pr.yml b/.github/workflows/gen-sui-upgrade-version-pr.yml index 0b1ba1bc05..77d330e47f 100644 --- a/.github/workflows/gen-sui-upgrade-version-pr.yml +++ b/.github/workflows/gen-sui-upgrade-version-pr.yml @@ -50,7 +50,7 @@ jobs: steps: - name: Checkout - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 with: persist-credentials: false @@ -78,7 +78,7 @@ jobs: - name: Generate automerge token id: automerge_token - uses: actions/create-github-app-token@29824e69f54612133e76f7eaac726eef6c875baf # pin@v2.2.1 + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # pin@v3.2.0 with: app-id: ${{ secrets.WALRUS_AUTOMERGE_APP_ID }} private-key: ${{ secrets.WALRUS_AUTOMERGE_PRIVATE_KEY }} diff --git a/.github/workflows/issues-monitor.yaml b/.github/workflows/issues-monitor.yaml index a102099de8..66abd5da42 100644 --- a/.github/workflows/issues-monitor.yaml +++ b/.github/workflows/issues-monitor.yaml @@ -10,7 +10,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Add Comment to New Issue - uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # pin@v8.0.0 + uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # pin@v9.0.0 with: script: | github.rest.issues.createComment({ diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml index 634c2d238f..0338fd7884 100644 --- a/.github/workflows/lint.yml +++ b/.github/workflows/lint.yml @@ -13,7 +13,7 @@ jobs: contents: read pull-requests: read steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 with: fetch-depth: 0 - name: Check PR title @@ -25,9 +25,9 @@ jobs: runs-on: ubuntu-latest name: Check formatting steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 - name: Set up Python - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # pin@v6.2.0 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # pin@v6.3.0 with: python-version: "3.x" @@ -59,7 +59,7 @@ jobs: run: ./yamlfmt -lint - name: Lint all markdown files - uses: DavidAnson/markdownlint-cli2-action@07035fd053f7be764496c0f8d8f9f41f98305101 # pin@v22.0.0 + uses: DavidAnson/markdownlint-cli2-action@ded1f9488f68a970bc66ea5619e13e9b52e601cd # pin@v23.2.0 with: config: .markdownlint-cli2.yaml # Note: Keep globs in sync with .markdownlint-cli2.yaml. @@ -72,7 +72,7 @@ jobs: run: working-directory: ./contracts steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 - name: Use Node.js uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # pin@v6.3.0 - run: npm install @mysten/prettier-plugin-move@0.3.0 @@ -82,14 +82,14 @@ jobs: runs-on: ubuntu-latest name: Check spelling steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 - - uses: crate-ci/typos@631208b7aac2daa8b707f55e7331f9112b0e062d # pin@v1.44.0 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 + - uses: crate-ci/typos@37bb98842b0d8c4ffebdb75301a13db0267cef89 # pin@v1.47.2 shellcheck: name: ShellCheck runs-on: ubuntu-latest steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 - name: Run ShellCheck run: find . -type f -name "*.sh" -exec shellcheck --severity=error {} + @@ -97,7 +97,7 @@ jobs: runs-on: ubuntu-latest name: Check license headers steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 - name: Install licensesnip uses: taiki-e/install-action@a2352fc6ce487f030a3aa709482d57823eadfb37 # pin@v2.75.16 with: @@ -108,9 +108,9 @@ jobs: runs-on: ubuntu-latest name: Check Network Reference is up to date steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 - name: Set up Python - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # pin@v6.2.0 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # pin@v6.3.0 with: python-version: "3.x" - name: Check for drift between the canonical sources and the page diff --git a/.github/workflows/notify-walrus-sites.yml b/.github/workflows/notify-walrus-sites.yml index 9997714137..f9a01705a4 100644 --- a/.github/workflows/notify-walrus-sites.yml +++ b/.github/workflows/notify-walrus-sites.yml @@ -26,7 +26,7 @@ jobs: steps: - name: Generate app token for cross-repo dispatch id: app_token - uses: actions/create-github-app-token@29824e69f54612133e76f7eaac726eef6c875baf # pin@v2.2.1 + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # pin@v3.2.0 with: app-id: ${{ secrets.WALRUS_AUTOMERGE_APP_ID }} private-key: ${{ secrets.WALRUS_AUTOMERGE_PRIVATE_KEY }} @@ -34,7 +34,7 @@ jobs: - name: Checkout walrus at release tag if: github.event_name == 'release' - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 with: ref: ${{ github.event.release.tag_name }} sparse-checkout: Cargo.toml diff --git a/.github/workflows/pages-preview.yaml b/.github/workflows/pages-preview.yaml index 3f33794b6a..87642b95d8 100644 --- a/.github/workflows/pages-preview.yaml +++ b/.github/workflows/pages-preview.yaml @@ -21,9 +21,9 @@ jobs: build-with-linkcheck: runs-on: ubuntu-latest steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 - name: Install pnpm - uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # pin@v5.0.0 + uses: pnpm/action-setup@0ebf47130e4866e96fce0953f49152a61190b271 # pin@v6.0.9 with: version: 9 if: github.event.action != 'closed' @@ -45,9 +45,9 @@ jobs: runs-on: ubuntu-latest if: github.repository_owner == 'MystenLabs' steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 - name: Install pnpm - uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # pin@v5.0.0 + uses: pnpm/action-setup@0ebf47130e4866e96fce0953f49152a61190b271 # pin@v6.0.9 with: version: 9 if: github.event.action != 'closed' @@ -75,7 +75,7 @@ jobs: if: github.event.action != 'closed' && github.repository_owner == 'MystenLabs' steps: - name: Wait for GitHub Pages deployment - uses: actions/github-script@v8 + uses: actions/github-script@v9 with: script: | // Wait for the Pages deployment triggered by the gh-pages push @@ -124,7 +124,7 @@ jobs: URL: https://MystenLabs.github.io/walrus/pr-preview/pr-${{ github.event.number }}/ - name: Comment on PR - uses: actions/github-script@v8 + uses: actions/github-script@v9 with: script: | const marker = ''; diff --git a/.github/workflows/publish-docs.yaml b/.github/workflows/publish-docs.yaml index 2125ff1457..0bbd8f5eaa 100644 --- a/.github/workflows/publish-docs.yaml +++ b/.github/workflows/publish-docs.yaml @@ -36,9 +36,9 @@ jobs: permissions: contents: write steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 - name: Install pnpm - uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # pin@v5.0.0 + uses: pnpm/action-setup@0ebf47130e4866e96fce0953f49152a61190b271 # pin@v6.0.9 with: version: 9 - name: Setup Node.js @@ -71,11 +71,11 @@ jobs: group: sui-wallet-operations cancel-in-progress: false steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 with: persist-credentials: false - name: Install pnpm - uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # pin@v5.0.0 + uses: pnpm/action-setup@0ebf47130e4866e96fce0953f49152a61190b271 # pin@v6.0.9 with: version: 9 - name: Setup Node.js diff --git a/.github/workflows/release-notes.yml b/.github/workflows/release-notes.yml index 506068b6a9..cc6a0dfdb2 100644 --- a/.github/workflows/release-notes.yml +++ b/.github/workflows/release-notes.yml @@ -24,7 +24,7 @@ jobs: isReleaseNotesEligible: ${{ steps.diff.outputs.isReleaseNotesEligible }} isReleaseNotesScript: ${{ steps.diff.outputs.isReleaseNotesScript }} steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 with: ref: ${{ github.event.inputs.sui_repo_ref || github.ref }} - name: Detect Changes @@ -40,10 +40,10 @@ jobs: pull-requests: read runs-on: [ubuntu-latest] steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 with: ref: ${{ github.event.inputs.sui_repo_ref || github.ref }} - - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # pin@v6.2.0 + - uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # pin@v6.3.0 with: python-version: 3.10.10 - name: Validate PR's release notes @@ -57,10 +57,10 @@ jobs: if: needs.diff.outputs.isReleaseNotesScript == 'true' runs-on: [ubuntu-latest] steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 with: ref: ${{ github.event.inputs.sui_repo_ref || github.ref }} - - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # pin@v6.2.0 + - uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # pin@v6.3.0 with: python-version: 3.10.10 - name: Install pytest diff --git a/.github/workflows/sccache-warmup.yml b/.github/workflows/sccache-warmup.yml index 928407ceb1..3a56a81a36 100644 --- a/.github/workflows/sccache-warmup.yml +++ b/.github/workflows/sccache-warmup.yml @@ -33,7 +33,7 @@ jobs: SCCACHE_GCS_RW_MODE: READ_WRITE RUSTC_WRAPPER: sccache steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 with: ref: main @@ -49,7 +49,7 @@ jobs: run: | sudo apt update && sudo apt install -y libpq-dev - - uses: mozilla-actions/sccache-action@7d986dd989559c6ecdb630a3fd2557667be217ad # pin@v0.0.9 + - uses: mozilla-actions/sccache-action@9e7fa8a12102821edf02ca5dbea1acd0f89a2696 # pin@v0.0.10 - name: Build workspace (debug) shell: bash diff --git a/.github/workflows/stale-prs.yaml b/.github/workflows/stale-prs.yaml index 4574d018a8..1bfb0fb46a 100644 --- a/.github/workflows/stale-prs.yaml +++ b/.github/workflows/stale-prs.yaml @@ -11,7 +11,7 @@ jobs: stale: runs-on: ubuntu-latest steps: - - uses: actions/stale@b5d41d4e1d5dceea10e7104786b73624c18a190f # pin@v10.2.0 + - uses: actions/stale@eb5cf3af3ac0a1aa4c9c45633dd1ae542a27a899 # pin@v10.3.0 with: stale-pr-message: > This PR is stale because it has been open 14 days with no activity. diff --git a/.github/workflows/tag.yml b/.github/workflows/tag.yml index 7b978a2f84..c5e91c9ba0 100644 --- a/.github/workflows/tag.yml +++ b/.github/workflows/tag.yml @@ -36,7 +36,7 @@ jobs: steps: - name: Checkout - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 - name: Tag uses: julbme/gh-action-manage-tag@8daf6387badea2c6b8f989bd0f82b5a9ef1d84e6 # pin@v1.0.1 diff --git a/.github/workflows/update-operators-cache.yml b/.github/workflows/update-operators-cache.yml index 86e609b981..c250dbfb61 100644 --- a/.github/workflows/update-operators-cache.yml +++ b/.github/workflows/update-operators-cache.yml @@ -24,7 +24,7 @@ jobs: update-cache: runs-on: ubuntu-latest steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 with: fetch-depth: 0 @@ -43,7 +43,7 @@ jobs: mv docs/site/static/new-operators.json docs/site/static/operators.json - name: Create Pull Request - uses: peter-evans/create-pull-request@c0f553fe549906ede9cf27b5156039d195d2ece0 # pin@v8.1.0 + uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # pin@v8.1.1 with: token: ${{ secrets.GITHUB_TOKEN }} commit-message: "chore: update aggregator cache info" diff --git a/.github/workflows/update-ws-binaries.yaml b/.github/workflows/update-ws-binaries.yaml index 321c41897a..36c899f67a 100644 --- a/.github/workflows/update-ws-binaries.yaml +++ b/.github/workflows/update-ws-binaries.yaml @@ -30,7 +30,7 @@ jobs: EPOCHS: 10 BUILD_DIR: site steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 - uses: ./.github/actions/set-up-walrus with: SUI_ADDRESS: "${{ vars.SUI_ADDRESS }}" diff --git a/.github/workflows/update-ws-install.yaml b/.github/workflows/update-ws-install.yaml index 459bab3ac8..887e4f8480 100644 --- a/.github/workflows/update-ws-install.yaml +++ b/.github/workflows/update-ws-install.yaml @@ -33,7 +33,7 @@ jobs: EPOCHS: max BUILD_DIR: site steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 - uses: ./.github/actions/set-up-walrus with: SUI_ADDRESS: "${{ vars.SUI_ADDRESS }}" diff --git a/.github/workflows/version-bump.yml b/.github/workflows/version-bump.yml index 69a9362637..0cc35d2a8a 100644 --- a/.github/workflows/version-bump.yml +++ b/.github/workflows/version-bump.yml @@ -68,7 +68,7 @@ jobs: fi - name: Checkout - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2 + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # pin@v7.0.0 - name: Configure git run: | @@ -108,7 +108,7 @@ jobs: - name: Generate automerge token if: inputs.delivery == 'pr' id: automerge_token - uses: actions/create-github-app-token@29824e69f54612133e76f7eaac726eef6c875baf # pin@v2.2.1 + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # pin@v3.2.0 with: app-id: ${{ secrets.WALRUS_AUTOMERGE_APP_ID }} private-key: ${{ secrets.WALRUS_AUTOMERGE_PRIVATE_KEY }}