diff --git a/.github/workflows/cloud-tests.yml b/.github/workflows/cloud-tests.yml index b3185741c..3d3b69950 100644 --- a/.github/workflows/cloud-tests.yml +++ b/.github/workflows/cloud-tests.yml @@ -56,7 +56,7 @@ jobs: - name: Configure AWS credentials if: github.event_name != 'workflow_dispatch' || github.actor != 'nektos/act' - uses: aws-actions/configure-aws-credentials@cbe3b392738ccf3f987d68400dafcf4b0624a56c # v6.2.4 + uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0 with: role-to-assume: "${{ secrets.TEST_ROLE_ARN }}" role-session-name: pythonTestingLibraryGitHubIntegrationTest diff --git a/.github/workflows/conformance-tests.yml b/.github/workflows/conformance-tests.yml index d1a1483ef..dbc482a85 100644 --- a/.github/workflows/conformance-tests.yml +++ b/.github/workflows/conformance-tests.yml @@ -76,7 +76,7 @@ jobs: python-version: "3.14" - name: Configure AWS credentials - uses: aws-actions/configure-aws-credentials@cbe3b392738ccf3f987d68400dafcf4b0624a56c # v6.2.4 + uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0 with: role-to-assume: "${{ secrets.TEST_ROLE_ARN }}" role-session-name: pythonConformanceTest diff --git a/.github/workflows/ecr-release.yml b/.github/workflows/ecr-release.yml index 11a0990d8..e436f88ed 100644 --- a/.github/workflows/ecr-release.yml +++ b/.github/workflows/ecr-release.yml @@ -46,7 +46,7 @@ jobs: - name: Set up QEMU for multi-platform builds if: matrix.arch == 'arm64' - uses: docker/setup-qemu-action@1f40c72289eff860ee54a304f1438e3cff362e0a # v4.3.0 + uses: docker/setup-qemu-action@99012661954931238ded8c8b007157a8430204e1 # v4.4.0 with: platforms: arm64 @@ -62,7 +62,7 @@ jobs: echo "VERSION=${VERSION}" >> "$GITHUB_OUTPUT" - name: Configure AWS Credentials - uses: aws-actions/configure-aws-credentials@cbe3b392738ccf3f987d68400dafcf4b0624a56c # v6.2.4 + uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0 with: role-to-assume: ${{ secrets.ECR_UPLOAD_IAM_ROLE_ARN }} aws-region: ${{ env.aws_region }} @@ -93,7 +93,7 @@ jobs: needs: [build-and-upload-image-to-ecr] steps: - name: Configure AWS Credentials - uses: aws-actions/configure-aws-credentials@cbe3b392738ccf3f987d68400dafcf4b0624a56c # v6.2.4 + uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0 with: role-to-assume: ${{ secrets.ECR_UPLOAD_IAM_ROLE_ARN }} aws-region: ${{ env.aws_region }} diff --git a/.github/workflows/issue-triage.yml b/.github/workflows/issue-triage.yml index ca1b69379..0a07ad1c2 100644 --- a/.github/workflows/issue-triage.yml +++ b/.github/workflows/issue-triage.yml @@ -12,5 +12,5 @@ jobs: contents: read id-token: write issues: write - uses: aws/aws-durable-execution-ci/.github/workflows/issue-triage.yml@8de63fa646c1b7b778829126cf53b7874074795e + uses: aws/aws-durable-execution-ci/.github/workflows/issue-triage.yml@d6b017da14385908951d23e26c790b28a4e5f9f0 secrets: inherit diff --git a/.github/workflows/lambda-layer-publish.yml b/.github/workflows/lambda-layer-publish.yml index a1e0dcf53..ae418a9ca 100644 --- a/.github/workflows/lambda-layer-publish.yml +++ b/.github/workflows/lambda-layer-publish.yml @@ -206,7 +206,7 @@ jobs: path: dist/ - name: Configure AWS credentials - uses: aws-actions/configure-aws-credentials@cbe3b392738ccf3f987d68400dafcf4b0624a56c # v6.2.4 + uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0 with: role-to-assume: ${{ secrets.LAYER_PUBLISH_ROLE_ARN }} role-session-name: otelLayerPublish diff --git a/.github/workflows/notify.yml b/.github/workflows/notify.yml index c3ebf17c0..c2eb601b2 100644 --- a/.github/workflows/notify.yml +++ b/.github/workflows/notify.yml @@ -16,7 +16,7 @@ jobs: contents: read models: read id-token: write - uses: aws/aws-durable-execution-ci/.github/workflows/notify.yml@8de63fa646c1b7b778829126cf53b7874074795e + uses: aws/aws-durable-execution-ci/.github/workflows/notify.yml@d6b017da14385908951d23e26c790b28a4e5f9f0 secrets: BEDROCK_ROLE_ARN: ${{ secrets.BEDROCK_ROLE_ARN }} SLACK_WEBHOOK_URL_PR: ${{ secrets.SLACK_WEBHOOK_URL_PR }} diff --git a/.github/workflows/opentelemetry-conformance-tests.yml b/.github/workflows/opentelemetry-conformance-tests.yml index 350577125..b31fff281 100644 --- a/.github/workflows/opentelemetry-conformance-tests.yml +++ b/.github/workflows/opentelemetry-conformance-tests.yml @@ -59,7 +59,7 @@ jobs: actions: write contents: read id-token: write - uses: aws/aws-durable-execution-conformance-tests/.github/workflows/opentelemetry-orchestrator.yml@c31f95f448a4fe8ffb93203c7920a48e87362801 + uses: aws/aws-durable-execution-conformance-tests/.github/workflows/opentelemetry-orchestrator.yml@a628f5589bbf067a441696c792ab3023c0d0899b with: language: python resource_prefix: p diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index cdbd2393b..214750982 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -75,6 +75,6 @@ jobs: # Upload the results to GitHub's code scanning dashboard (optional). # Commenting out will disable upload of results to your repo's Code Scanning dashboard - name: "Upload to code-scanning" - uses: github/codeql-action/upload-sarif@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 + uses: github/codeql-action/upload-sarif@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 with: sarif_file: results.sarif diff --git a/.github/workflows/stale-issue-closer.yml b/.github/workflows/stale-issue-closer.yml index 945b3192a..e8e59137b 100644 --- a/.github/workflows/stale-issue-closer.yml +++ b/.github/workflows/stale-issue-closer.yml @@ -14,4 +14,4 @@ jobs: permissions: contents: read issues: write - uses: aws/aws-durable-execution-ci/.github/workflows/stale-issue-closer.yml@1ce65d9d6bf531169718a5e967e15d72fc958265 + uses: aws/aws-durable-execution-ci/.github/workflows/stale-issue-closer.yml@48b3b4349f7d00a6212b9d959427bd7df81ea99d