diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..f6faee6 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,10 @@ +version: 2 +updates: + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "weekly" + groups: + github-actions: + patterns: + - "*" diff --git a/.github/workflows/issues.yml b/.github/workflows/issues.yml index 9634a0e..c935a8d 100644 --- a/.github/workflows/issues.yml +++ b/.github/workflows/issues.yml @@ -9,4 +9,4 @@ permissions: jobs: help-wanted: - uses: laravel/.github/.github/workflows/issues.yml@main + uses: laravel/.github/.github/workflows/issues.yml@dd86ce0a18475504e42fa809d7454c1cb1a88028 # main diff --git a/.github/workflows/pull-requests.yml b/.github/workflows/pull-requests.yml index 18b32b3..a4914b6 100644 --- a/.github/workflows/pull-requests.yml +++ b/.github/workflows/pull-requests.yml @@ -9,4 +9,4 @@ permissions: jobs: uneditable: - uses: laravel/.github/.github/workflows/pull-requests.yml@main + uses: laravel/.github/.github/workflows/pull-requests.yml@dd86ce0a18475504e42fa809d7454c1cb1a88028 # main diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index 6efb181..1d04ab3 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -9,6 +9,9 @@ on: schedule: - cron: '0 0 * * *' +permissions: + contents: read + jobs: tests: runs-on: ubuntu-24.04 @@ -45,10 +48,12 @@ jobs: steps: - name: Checkout code - uses: actions/checkout@v6 + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 + with: + persist-credentials: false - name: Setup PHP - uses: shivammathur/setup-php@v2 + uses: shivammathur/setup-php@7c071dfe9dc99bdf297fa79cb49ea005b9fcadbc # v2 with: php-version: ${{ matrix.php }} extensions: dom, curl, libxml, mbstring, redis, zip diff --git a/.github/workflows/update-changelog.yml b/.github/workflows/update-changelog.yml index ebda620..674a96e 100644 --- a/.github/workflows/update-changelog.yml +++ b/.github/workflows/update-changelog.yml @@ -10,4 +10,4 @@ jobs: update: permissions: contents: write - uses: laravel/.github/.github/workflows/update-changelog.yml@main + uses: laravel/.github/.github/workflows/update-changelog.yml@dd86ce0a18475504e42fa809d7454c1cb1a88028 # main