Skip to content

Commit 352c339

Browse files
vNeeL-codeclaude
andcommitted
Fix CI: replace broken SHA-pinned actions with version tags
The commit-SHA pinned actions (from security audit) stopped resolving. Switched to stable version tags: @v4 for checkout/java/gradle, @v2 for gh-release. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
1 parent 5aa34a9 commit 352c339

File tree

1 file changed

+4
-8
lines changed

1 file changed

+4
-8
lines changed

.github/workflows/release.yml

Lines changed: 4 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -13,19 +13,16 @@ jobs:
1313
runs-on: ubuntu-latest
1414

1515
steps:
16-
# actions/checkout@v4.2.2 (Pinned for security)
17-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
16+
- uses: actions/checkout@v4
1817

19-
# actions/setup-java@v5.2.0 (Latest 2026 stable)
2018
- name: Set up JDK 17
21-
uses: actions/setup-java@be666c2d398991f855e37f8f121d5c219485b0d0
19+
uses: actions/setup-java@v4
2220
with:
2321
java-version: '17'
2422
distribution: 'temurin'
2523

26-
# gradle/actions/setup-gradle@v4.3.0 (Official Gradle build tool)
2724
- name: Setup Gradle
28-
uses: gradle/actions/setup-gradle@417ae30571c208c1d5683939634f669d45a052d0
25+
uses: gradle/actions/setup-gradle@v4
2926

3027
- name: Make gradlew executable
3128
run: chmod +x ./gradlew
@@ -62,9 +59,8 @@ jobs:
6259
APK=$(find app/build/outputs/apk/release -name "*.apk" | head -1)
6360
cp "$APK" "app/build/outputs/apk/release/Oracle_OS-${VERSION}.apk"
6461
65-
# softprops/action-gh-release@v2.5.0 (The delivery truck driver)
6662
- name: Create GitHub Release
67-
uses: softprops/action-gh-release@a06a81af2036c6416629e46a5827725925cf1564
63+
uses: softprops/action-gh-release@v2
6864
with:
6965
files: app/build/outputs/apk/release/Oracle_OS-*.apk
7066
generate_release_notes: true

0 commit comments

Comments
 (0)