@@ -15,11 +15,11 @@ jobs:
1515 name : Build distributions 📦
1616 runs-on : ubuntu-latest
1717 steps :
18- - uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
18+ - uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
1919 with :
2020 persist-credentials : false
2121
22- - uses : actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5
22+ - uses : actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0
2323 with :
2424 python-version-file : pyproject.toml
2525 cache : " pip"
3232 run : python -m build
3333
3434 - name : Upload distributions
35- uses : actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
35+ uses : actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
3636 with :
3737 name : distributions
3838 path : dist/
@@ -46,12 +46,12 @@ jobs:
4646 attestations : write # to persist the attestation files
4747 steps :
4848 - name : Download distributions
49- uses : actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
49+ uses : actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
5050 with :
5151 name : distributions
5252 path : dist/
5353 - name : Create provenances
54- uses : actions/attest-build-provenance@v2
54+ uses : actions/attest-build-provenance@db473fddc028af60658334401dc6fa3ffd8669fd # v2.3.0
5555 with :
5656 subject-path : ' dist/*'
5757
@@ -67,12 +67,12 @@ jobs:
6767
6868 steps :
6969 - name : Download distributions
70- uses : actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
70+ uses : actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
7171 with :
7272 name : distributions
7373 path : dist/
7474
7575 - name : publish
76- uses : pypa/gh-action-pypi-publish@release/v1
76+ uses : pypa/gh-action-pypi-publish@76f52bc884231f62b9a034ebfe128415bbaabdfc # v1.12.4
7777 with :
7878 attestations : true
0 commit comments