diff --git a/.github/workflows/devcontainer-build-publish.yaml b/.github/workflows/devcontainer-build-publish.yaml index 87ef063..5cf73b0 100644 --- a/.github/workflows/devcontainer-build-publish.yaml +++ b/.github/workflows/devcontainer-build-publish.yaml @@ -27,7 +27,7 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 #v7.0.1 - name: "Set up Node.js" - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: "22" diff --git a/.github/workflows/jekyll-gh-pages.yml b/.github/workflows/jekyll-gh-pages.yml index 0a40e77..14bd9cf 100644 --- a/.github/workflows/jekyll-gh-pages.yml +++ b/.github/workflows/jekyll-gh-pages.yml @@ -32,7 +32,7 @@ jobs: steps: - name: Checkout uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 #v7.0.1 - - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 + - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: 22 - run: npm ci --ignore-scripts @@ -45,7 +45,7 @@ jobs: working-directory: "./docs" - name: Setup Pages id: pages - uses: actions/configure-pages@983d7736d9b0ae728b81ab479565c72886d7745b # v5 + uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6.0.0 - name: Build with Jekyll working-directory: ./docs # Outputs to the './_site' directory by default @@ -54,11 +54,11 @@ jobs: JEKYLL_ENV: production - name: Upload artifact # Automatically uploads an artifact from the './_site' directory by default - uses: actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa # v3 + uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0 with: path: "docs/_site/" - name: Archive production artifacts - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: site path: "docs/_site/" @@ -76,4 +76,4 @@ jobs: steps: - name: Deploy to GitHub Pages id: deployment - uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e # v4 + uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 # v5.0.1 diff --git a/.github/workflows/release-notes-sync.yaml b/.github/workflows/release-notes-sync.yaml index de9fb77..dbd4ed2 100644 --- a/.github/workflows/release-notes-sync.yaml +++ b/.github/workflows/release-notes-sync.yaml @@ -22,7 +22,7 @@ jobs: private-key: "${{ secrets.APP_PEM_FILE }}" - name: "Checkout code" - uses: actions/checkout@v4 + uses: actions/checkout@v7 - name: "Update release notes data" uses: ./.github/actions/release-notes diff --git a/.github/workflows/stage-1-commit.yaml b/.github/workflows/stage-1-commit.yaml index afcfeb1..9c85a76 100644 --- a/.github/workflows/stage-1-commit.yaml +++ b/.github/workflows/stage-1-commit.yaml @@ -46,7 +46,7 @@ jobs: with: fetch-depth: 0 # Full history is needed to scan all commits - name: "Scan secrets" - uses: NHSDigital/nhs-notify-shared-modules/.github/actions/scan-secrets@5.1.3 # NOSONAR - githubactions:S7637 - internally controlled repo, pinned by tag + uses: NHSDigital/nhs-notify-shared-modules/.github/actions/scan-secrets@6.0.5 # NOSONAR - githubactions:S7637 - internally controlled repo, pinned by tag validate-action-pins: name: "Validate action SHA pins" runs-on: ubuntu-latest @@ -55,7 +55,7 @@ jobs: - name: "Checkout code" uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: "Validate action SHA pins" - uses: NHSDigital/nhs-notify-shared-modules/.github/actions/validate-action-pins@5.1.3 # NOSONAR - githubactions:S7637 - internally controlled repo, pinned by tag + uses: NHSDigital/nhs-notify-shared-modules/.github/actions/validate-action-pins@6.0.5 # NOSONAR - githubactions:S7637 - internally controlled repo, pinned by tag check-file-format: name: "Check file format" runs-on: ubuntu-latest @@ -66,7 +66,7 @@ jobs: with: fetch-depth: 0 # Full history is needed to compare branches - name: "Check file format" - uses: NHSDigital/nhs-notify-shared-modules/.github/actions/check-file-format@5.1.3 # NOSONAR - githubactions:S7637 - internally controlled repo, pinned by tag + uses: NHSDigital/nhs-notify-shared-modules/.github/actions/check-file-format@6.0.5 # NOSONAR - githubactions:S7637 - internally controlled repo, pinned by tag check-markdown-format: name: "Check Markdown format" runs-on: ubuntu-latest @@ -77,7 +77,7 @@ jobs: with: fetch-depth: 0 # Full history is needed to compare branches - name: "Check Markdown format" - uses: NHSDigital/nhs-notify-shared-modules/.github/actions/check-markdown-format@5.1.3 # NOSONAR - githubactions:S7637 - internally controlled repo, pinned by tag + uses: NHSDigital/nhs-notify-shared-modules/.github/actions/check-markdown-format@6.0.5 # NOSONAR - githubactions:S7637 - internally controlled repo, pinned by tag check-english-usage: name: "Check English usage" runs-on: ubuntu-latest @@ -88,7 +88,7 @@ jobs: with: fetch-depth: 0 # Full history is needed to compare branches - name: "Check English usage" - uses: NHSDigital/nhs-notify-shared-modules/.github/actions/check-english-usage@5.1.3 # NOSONAR - githubactions:S7637 - internally controlled repo, pinned by tag + uses: NHSDigital/nhs-notify-shared-modules/.github/actions/check-english-usage@6.0.5 # NOSONAR - githubactions:S7637 - internally controlled repo, pinned by tag count-lines-of-code: name: "Count lines of code" runs-on: ubuntu-latest @@ -100,7 +100,7 @@ jobs: - name: "Checkout code" uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 #v7.0.1 - name: "Count lines of code" - uses: NHSDigital/nhs-notify-shared-modules/.github/actions/create-lines-of-code-report@5.1.3 # NOSONAR - githubactions:S7637 - internally controlled repo, pinned by tag + uses: NHSDigital/nhs-notify-shared-modules/.github/actions/create-lines-of-code-report@6.0.5 # NOSONAR - githubactions:S7637 - internally controlled repo, pinned by tag with: build_datetime: "${{ inputs.build_datetime }}" build_timestamp: "${{ inputs.build_timestamp }}" @@ -120,7 +120,7 @@ jobs: - name: "Checkout code" uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 #v7.0.1 - name: "Scan dependencies" - uses: NHSDigital/nhs-notify-shared-modules/.github/actions/scan-dependencies@3.0.9 + uses: NHSDigital/nhs-notify-shared-modules/.github/actions/scan-dependencies@6.0.5 with: build_datetime: "${{ inputs.build_datetime }}" build_timestamp: "${{ inputs.build_timestamp }}" diff --git a/.github/workflows/stage-2-test.yaml b/.github/workflows/stage-2-test.yaml index 55b4c7f..8861da7 100644 --- a/.github/workflows/stage-2-test.yaml +++ b/.github/workflows/stage-2-test.yaml @@ -87,7 +87,7 @@ jobs: with: fetch-depth: 0 # Full history is needed to improving relevancy of reporting - name: "Perform static analysis" - uses: NHSDigital/nhs-notify-shared-modules/.github/actions/perform-static-analysis@5.1.0 # NOSONAR - githubactions:S7637 - internally controlled repo, pinned by tag + uses: NHSDigital/nhs-notify-shared-modules/.github/actions/perform-static-analysis@6.0.5 # NOSONAR - githubactions:S7637 - internally controlled repo, pinned by tag with: sonar_organisation_key: "${{ vars.SONAR_ORGANISATION_KEY }}" sonar_project_key: "${{ vars.SONAR_PROJECT_KEY }}" diff --git a/.github/workflows/stage-4-acceptance.yaml b/.github/workflows/stage-4-acceptance.yaml index c113d04..459da22 100644 --- a/.github/workflows/stage-4-acceptance.yaml +++ b/.github/workflows/stage-4-acceptance.yaml @@ -127,7 +127,7 @@ jobs: steps: - name: "Checkout code" uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 #v7.0.1 - - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 + - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: 22 - run: npm ci # Sonar: --ignore-scripts breaks playwright installation for Pa11y @@ -141,7 +141,7 @@ jobs: working-directory: "./docs" - name: Setup Pages id: pages - uses: actions/configure-pages@983d7736d9b0ae728b81ab479565c72886d7745b # v5 + uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6.0.0 with: working-directory: "./docs" - name: Build with Jekyll @@ -152,7 +152,7 @@ jobs: - name: Run accessibility test run: make test-accessibility - name: Archive accessibility results - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: accessibility path: "docs/.reports/accessibility"