@@ -49,24 +49,24 @@ jobs:
4949 - os : macos-13
5050 test-java-version : 23
5151 steps :
52- - uses : actions/checkout@v4
52+ - uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
5353
5454 - id : setup-java-test
5555 name : Set up Java ${{ matrix.test-java-version }} for tests
56- uses : actions/setup-java@v4
56+ uses : actions/setup-java@3a4f6e1af504cf6a31855fa899c6aa5355ba6c12 # v4.7.0
5757 with :
5858 distribution : temurin
5959 java-version : ${{ matrix.test-java-version }}
6060
6161 - id : setup-java
6262 name : Set up Java for build
63- uses : actions/setup-java@v4
63+ uses : actions/setup-java@3a4f6e1af504cf6a31855fa899c6aa5355ba6c12 # v4.7.0
6464 with :
6565 distribution : temurin
6666 java-version : 17
6767
6868 - name : Set up gradle
69- uses : gradle/actions/setup-gradle@v4
69+ uses : gradle/actions/setup-gradle@94baf225fe0a508e581a564467443d0e2379123b # v4.3.0
7070 - name : Build
7171 run : >
7272 ./gradlew build
@@ -96,12 +96,12 @@ jobs:
9696 exit 1
9797 fi
9898
99- - uses : codecov/codecov-action@v5
99+ - uses : codecov/codecov-action@13ce06bfc6bbe3ecf90edbbf1bc32fe5978ca1d3 # v5.3.1
100100 if : ${{ matrix.coverage }}
101101 env :
102102 CODECOV_TOKEN : ${{ secrets.CODECOV_TOKEN }}
103103
104- - uses : actions/upload-artifact@v4
104+ - uses : actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
105105 if : ${{ matrix.coverage }}
106106 with :
107107 name : coverage-report
@@ -132,17 +132,17 @@ jobs:
132132 needs : build
133133 runs-on : ubuntu-24.04
134134 steps :
135- - uses : actions/checkout@v4
135+ - uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
136136
137137 - id : setup-java
138138 name : Set up Java
139- uses : actions/setup-java@v4
139+ uses : actions/setup-java@3a4f6e1af504cf6a31855fa899c6aa5355ba6c12 # v4.7.0
140140 with :
141141 distribution : temurin
142142 java-version : 17
143143
144144 - name : Set up gradle
145- uses : gradle/actions/setup-gradle@v4
145+ uses : gradle/actions/setup-gradle@94baf225fe0a508e581a564467443d0e2379123b # v4.3.0
146146 # skipping release branches because the versions in those branches are not snapshots
147147 # (also this skips pull requests)
148148 if : ${{ github.ref_name == 'main' && github.repository == 'open-telemetry/opentelemetry-java' }}
@@ -160,8 +160,8 @@ jobs:
160160 build-graal :
161161 runs-on : ubuntu-latest
162162 steps :
163- - uses : actions/checkout@v4
164- - uses : graalvm/setup-graalvm@v1
163+ - uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
164+ - uses : graalvm/setup-graalvm@aafbedb8d382ed0ca6167d3a051415f20c859274 # v1.2.8
165165 with :
166166 # TODO(jack-berg): Which versions do we need to test? Should we use a matrix scheme?
167167 java-version : ' 21'
0 commit comments