From 4a9a1859bb7b342c0ce9fa8a55974c6f0a0b82af Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Thu, 30 Oct 2025 17:58:38 +0000 Subject: [PATCH] chore(deps): pin dependencies --- .github/workflows/build-artifacts.yml | 6 +- .github/workflows/ci.yml | 6 +- .github/workflows/release.yml | 10 +-- Cargo.lock | 6 +- Cargo.toml | 2 +- docs/themes/purehugo/package.json | 8 +- package-lock.json | 121 ++++++++++++++++++-------- package.json | 8 +- 8 files changed, 109 insertions(+), 58 deletions(-) diff --git a/.github/workflows/build-artifacts.yml b/.github/workflows/build-artifacts.yml index 56e0112..97d213d 100644 --- a/.github/workflows/build-artifacts.yml +++ b/.github/workflows/build-artifacts.yml @@ -55,7 +55,7 @@ jobs: contents: read steps: - name: Checkout - uses: actions/checkout@v5 + uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5 with: fetch-depth: ${{ inputs.fetch_depth }} @@ -64,7 +64,7 @@ jobs: with: toolchain: ${{ inputs.toolchain }} - name: Rust Cache - uses: Swatinem/rust-cache@v2.8.1 + uses: Swatinem/rust-cache@f13886b937689c021905a6b90929199931d60db1 # v2.8.1 - name: Install musl toolchain if: ${{ inputs.rpm }} run: | @@ -122,7 +122,7 @@ jobs: - name: Upload artifacts if: ${{ inputs.upload_artifact && steps.build.outcome == 'success' }} - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 with: name: ${{ inputs.artifact_name }} path: dist diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index d990867..f8d17d5 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -15,13 +15,13 @@ jobs: name: Linting and Formatting runs-on: ubuntu-latest steps: - - uses: actions/checkout@v5 + - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5 - name: Install rust uses: dtolnay/rust-toolchain@master with: toolchain: stable - name: Rust Cache - uses: Swatinem/rust-cache@v2.8.1 + uses: Swatinem/rust-cache@f13886b937689c021905a6b90929199931d60db1 # v2.8.1 - name: Run cargo clippy to pick up any errors run: cargo clippy --all-targets -- -Dwarnings - name: Check code is formatted @@ -90,7 +90,7 @@ jobs: needs: build steps: - name: Download linux artifacts - uses: actions/download-artifact@v6 + uses: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53 # v6 with: name: dist-linux path: dist-linux diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 9d5e4b4..8231522 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -9,7 +9,7 @@ permissions: jobs: get-next-version: - uses: semantic-release-action/next-release-version/.github/workflows/next-release-version.yml@v4 + uses: semantic-release-action/next-release-version/.github/workflows/next-release-version.yml@0cdefe1224944c23645e5131f7a5189672c0df92 # v4 build-artifacts: name: Build ${{ matrix.name }} artifacts @@ -54,7 +54,7 @@ jobs: pull-requests: write steps: - name: Checkout - uses: actions/checkout@v5 + uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5 with: fetch-depth: 0 @@ -64,13 +64,13 @@ jobs: toolchain: stable - name: Rust Cache - uses: Swatinem/rust-cache@v2.8.1 + uses: Swatinem/rust-cache@f13886b937689c021905a6b90929199931d60db1 # v2.8.1 - name: Install semantic-release-cargo run: cargo install --locked semantic-release-cargo - name: Setup Node.js - uses: actions/setup-node@v4 + uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4 with: node-version: "node" @@ -78,7 +78,7 @@ jobs: run: npm ci - name: Download build artifacts - uses: actions/download-artifact@v4 + uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4 with: pattern: dist-* merge-multiple: true diff --git a/Cargo.lock b/Cargo.lock index a75ec37..726e010 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -981,15 +981,15 @@ dependencies = [ [[package]] name = "tempfile" -version = "3.23.0" +version = "3.19.1" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "2d31c77bdf42a745371d260a26ca7163f1e0924b64afa0b688e61b5a9fa02f16" +checksum = "7437ac7763b9b123ccf33c338a5cc1bac6f69b45a136c19bdd8a65e3916435bf" dependencies = [ "fastrand", "getrandom 0.3.3", "once_cell", "rustix", - "windows-sys 0.60.2", + "windows-sys 0.59.0", ] [[package]] diff --git a/Cargo.toml b/Cargo.toml index 79fb5e0..6e8a317 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -35,7 +35,7 @@ toml = "0.9.0" shell-words = "1.1.0" [dev-dependencies] -tempfile = "3.19.1" +tempfile = "=3.19.1" [package.metadata.generate-rpm] assets = [ diff --git a/docs/themes/purehugo/package.json b/docs/themes/purehugo/package.json index 81dd8a1..898c908 100644 --- a/docs/themes/purehugo/package.json +++ b/docs/themes/purehugo/package.json @@ -1,8 +1,8 @@ { "devDependencies": { - "gulp": "^5.0.0", - "gulp-concat": "^2.5.2", - "gulp-minify-css": "^1.1.0", - "gulp-uglify": "^3.0.0" + "gulp": "5.0.1", + "gulp-concat": "2.6.1", + "gulp-minify-css": "1.2.4", + "gulp-uglify": "3.0.2" } } diff --git a/package-lock.json b/package-lock.json index e201bc7..92a392f 100644 --- a/package-lock.json +++ b/package-lock.json @@ -6,10 +6,10 @@ "packages": { "": { "devDependencies": { - "@semantic-release/commit-analyzer": "^13.0.1", - "@semantic-release/exec": "^7.1.0", - "@semantic-release/release-notes-generator": "^14.0.3", - "semantic-release": "^24.2.5" + "@semantic-release/commit-analyzer": "13.0.1", + "@semantic-release/exec": "7.1.0", + "@semantic-release/release-notes-generator": "14.1.0", + "semantic-release": "24.2.9" } }, "node_modules/@babel/code-frame": { @@ -64,6 +64,7 @@ "integrity": "sha512-t54CUOsFMappY1Jbzb7fetWeO0n6K0k/4+/ZpkS+3Joz8I4VcvY9OiEBFRYISqaI2fq5sCiPtAjRDOzVYG8m+Q==", "dev": true, "license": "MIT", + "peer": true, "dependencies": { "@octokit/auth-token": "^6.0.0", "@octokit/graphql": "^9.0.2", @@ -310,6 +311,83 @@ "semantic-release": ">=24.1.0" } }, + "node_modules/@semantic-release/github": { + "version": "11.0.6", + "resolved": "https://registry.npmjs.org/@semantic-release/github/-/github-11.0.6.tgz", + "integrity": "sha512-ctDzdSMrT3H+pwKBPdyCPty6Y47X8dSrjd3aPZ5KKIKKWTwZBE9De8GtsH3TyAlw3Uyo2stegMx6rJMXKpJwJA==", + "dev": true, + "license": "MIT", + "dependencies": { + "@octokit/core": "^7.0.0", + "@octokit/plugin-paginate-rest": "^13.0.0", + "@octokit/plugin-retry": "^8.0.0", + "@octokit/plugin-throttling": "^11.0.0", + "@semantic-release/error": "^4.0.0", + "aggregate-error": "^5.0.0", + "debug": "^4.3.4", + "dir-glob": "^3.0.1", + "http-proxy-agent": "^7.0.0", + "https-proxy-agent": "^7.0.0", + "issue-parser": "^7.0.0", + "lodash-es": "^4.17.21", + "mime": "^4.0.0", + "p-filter": "^4.0.0", + "tinyglobby": "^0.2.14", + "url-join": "^5.0.0" + }, + "engines": { + "node": ">=20.8.1" + }, + "peerDependencies": { + "semantic-release": ">=24.1.0" + } + }, + "node_modules/@semantic-release/github/node_modules/aggregate-error": { + "version": "5.0.0", + "resolved": "https://registry.npmjs.org/aggregate-error/-/aggregate-error-5.0.0.tgz", + "integrity": "sha512-gOsf2YwSlleG6IjRYG2A7k0HmBMEo6qVNk9Bp/EaLgAJT5ngH6PXbqa4ItvnEwCm/velL5jAnQgsHsWnjhGmvw==", + "dev": true, + "license": "MIT", + "dependencies": { + "clean-stack": "^5.2.0", + "indent-string": "^5.0.0" + }, + "engines": { + "node": ">=18" + }, + "funding": { + "url": "https://github.com/sponsors/sindresorhus" + } + }, + "node_modules/@semantic-release/github/node_modules/clean-stack": { + "version": "5.3.0", + "resolved": "https://registry.npmjs.org/clean-stack/-/clean-stack-5.3.0.tgz", + "integrity": "sha512-9ngPTOhYGQqNVSfeJkYXHmF7AGWp4/nN5D/QqNQs3Dvxd1Kk/WpjHfNujKHYUQ/5CoGyOyFNoWSPk5afzP0QVg==", + "dev": true, + "license": "MIT", + "dependencies": { + "escape-string-regexp": "5.0.0" + }, + "engines": { + "node": ">=14.16" + }, + "funding": { + "url": "https://github.com/sponsors/sindresorhus" + } + }, + "node_modules/@semantic-release/github/node_modules/indent-string": { + "version": "5.0.0", + "resolved": "https://registry.npmjs.org/indent-string/-/indent-string-5.0.0.tgz", + "integrity": "sha512-m6FAo/spmsW2Ab2fU35JTYwtOKa2yAwXSwgjSv1TJzh4Mh7mC3lzAOVLBprb72XsTrgkEIsl7YrFNAiDiRhIGg==", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=12" + }, + "funding": { + "url": "https://github.com/sponsors/sindresorhus" + } + }, "node_modules/@semantic-release/npm": { "version": "12.0.2", "resolved": "https://registry.npmjs.org/@semantic-release/npm/-/npm-12.0.2.tgz", @@ -1879,6 +1957,7 @@ "integrity": "sha512-8dD6FusOQSrpv9Z1rdNMdlSgQOIP880DHqnohobOmYLElGEqAL/JvxvuxZO16r4HtjTlfPRDC1hbvxC9dPN2nA==", "dev": true, "license": "MIT", + "peer": true, "bin": { "marked": "bin/marked.js" }, @@ -4520,6 +4599,7 @@ "dev": true, "inBundle": true, "license": "MIT", + "peer": true, "engines": { "node": ">=12" }, @@ -5199,6 +5279,7 @@ "integrity": "sha512-phCkJ6pjDi9ANdhuF5ElS10GGdAKY6R1Pvt9lT3SFhOwM4T7QZE7MLpBDbNruUx/Q3gFD92/UOFringGipRqZA==", "dev": true, "license": "MIT", + "peer": true, "dependencies": { "@semantic-release/commit-analyzer": "^13.0.0-beta.1", "@semantic-release/error": "^4.0.0", @@ -5237,37 +5318,6 @@ "node": ">=20.8.1" } }, - "node_modules/semantic-release/node_modules/@semantic-release/github": { - "version": "11.0.6", - "resolved": "https://registry.npmjs.org/@semantic-release/github/-/github-11.0.6.tgz", - "integrity": "sha512-ctDzdSMrT3H+pwKBPdyCPty6Y47X8dSrjd3aPZ5KKIKKWTwZBE9De8GtsH3TyAlw3Uyo2stegMx6rJMXKpJwJA==", - "dev": true, - "license": "MIT", - "dependencies": { - "@octokit/core": "^7.0.0", - "@octokit/plugin-paginate-rest": "^13.0.0", - "@octokit/plugin-retry": "^8.0.0", - "@octokit/plugin-throttling": "^11.0.0", - "@semantic-release/error": "^4.0.0", - "aggregate-error": "^5.0.0", - "debug": "^4.3.4", - "dir-glob": "^3.0.1", - "http-proxy-agent": "^7.0.0", - "https-proxy-agent": "^7.0.0", - "issue-parser": "^7.0.0", - "lodash-es": "^4.17.21", - "mime": "^4.0.0", - "p-filter": "^4.0.0", - "tinyglobby": "^0.2.14", - "url-join": "^5.0.0" - }, - "engines": { - "node": ">=20.8.1" - }, - "peerDependencies": { - "semantic-release": ">=24.1.0" - } - }, "node_modules/semantic-release/node_modules/aggregate-error": { "version": "5.0.0", "resolved": "https://registry.npmjs.org/aggregate-error/-/aggregate-error-5.0.0.tgz", @@ -5886,6 +5936,7 @@ "integrity": "sha512-5gTmgEY/sqK6gFXLIsQNH19lWb4ebPDLA4SdLP7dsWkIXHWlG66oPuVvXSGFPppYZz8ZDZq0dYYrbHfBCVUb1Q==", "dev": true, "license": "MIT", + "peer": true, "engines": { "node": ">=12" }, diff --git a/package.json b/package.json index 3520145..07a1bbf 100644 --- a/package.json +++ b/package.json @@ -1,8 +1,8 @@ { "devDependencies": { - "@semantic-release/commit-analyzer": "^13.0.1", - "@semantic-release/exec": "^7.1.0", - "@semantic-release/release-notes-generator": "^14.0.3", - "semantic-release": "^24.2.5" + "@semantic-release/commit-analyzer": "13.0.1", + "@semantic-release/exec": "7.1.0", + "@semantic-release/release-notes-generator": "14.1.0", + "semantic-release": "24.2.9" } }