This is an automated email from the ASF dual-hosted git repository.

yihua pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/hudi.git


The following commit(s) were added to refs/heads/master by this push:
     new 4290550378d1 chore: Pin third-party GitHub Actions to commit SHAs 
(#18872)
4290550378d1 is described below

commit 4290550378d134496e81d06a33deb75533b0b0eb
Author: Arpit Jain <[email protected]>
AuthorDate: Fri May 29 01:43:33 2026 +0900

    chore: Pin third-party GitHub Actions to commit SHAs (#18872)
    
    Signed-off-by: Arpit Jain <[email protected]>
---
 .github/workflows/bot.yml                 | 28 ++++++++++++++--------------
 .github/workflows/pr_title_validation.yml |  2 +-
 2 files changed, 15 insertions(+), 15 deletions(-)

diff --git a/.github/workflows/bot.yml b/.github/workflows/bot.yml
index 0f4950993773..ebeb41caf4f9 100644
--- a/.github/workflows/bot.yml
+++ b/.github/workflows/bot.yml
@@ -141,7 +141,7 @@ jobs:
         run: ./scripts/jacoco/generate_merged_coverage_report.sh 
$GITHUB_WORKSPACE
       - name: Upload coverage to Codecov
         if: always() && needs.changes.outputs.relevant == 'true'
-        uses: codecov/codecov-action@v5
+        uses: codecov/codecov-action@75cd11691c0faa626561e295848008c8a7dddffe 
# v5
         with:
           files: ./jacoco-report.xml
           disable_search: true
@@ -199,7 +199,7 @@ jobs:
         run: ./scripts/jacoco/generate_merged_coverage_report.sh 
$GITHUB_WORKSPACE
       - name: Upload coverage to Codecov
         if: always() && needs.changes.outputs.relevant == 'true'
-        uses: codecov/codecov-action@v5
+        uses: codecov/codecov-action@75cd11691c0faa626561e295848008c8a7dddffe 
# v5
         with:
           files: ./jacoco-report.xml
           disable_search: true
@@ -298,7 +298,7 @@ jobs:
         run: ./scripts/jacoco/generate_merged_coverage_report.sh 
$GITHUB_WORKSPACE
       - name: Upload coverage to Codecov
         if: always() && needs.changes.outputs.relevant == 'true'
-        uses: codecov/codecov-action@v5
+        uses: codecov/codecov-action@75cd11691c0faa626561e295848008c8a7dddffe 
# v5
         with:
           files: ./jacoco-report.xml
           disable_search: true
@@ -351,7 +351,7 @@ jobs:
         run: ./scripts/jacoco/generate_merged_coverage_report.sh 
$GITHUB_WORKSPACE
       - name: Upload coverage to Codecov
         if: always() && needs.changes.outputs.relevant == 'true'
-        uses: codecov/codecov-action@v5
+        uses: codecov/codecov-action@75cd11691c0faa626561e295848008c8a7dddffe 
# v5
         with:
           files: ./jacoco-report.xml
           disable_search: true
@@ -419,7 +419,7 @@ jobs:
         run: ./scripts/jacoco/generate_merged_coverage_report.sh 
$GITHUB_WORKSPACE
       - name: Upload coverage to Codecov
         if: always() && needs.changes.outputs.relevant == 'true'
-        uses: codecov/codecov-action@v5
+        uses: codecov/codecov-action@75cd11691c0faa626561e295848008c8a7dddffe 
# v5
         with:
           files: ./jacoco-report.xml
           disable_search: true
@@ -480,7 +480,7 @@ jobs:
         run: ./scripts/jacoco/generate_merged_coverage_report.sh 
$GITHUB_WORKSPACE
       - name: Upload coverage to Codecov
         if: always() && needs.changes.outputs.relevant == 'true'
-        uses: codecov/codecov-action@v5
+        uses: codecov/codecov-action@75cd11691c0faa626561e295848008c8a7dddffe 
# v5
         with:
           files: ./jacoco-report.xml
           disable_search: true
@@ -541,7 +541,7 @@ jobs:
         run: ./scripts/jacoco/generate_merged_coverage_report.sh 
$GITHUB_WORKSPACE
       - name: Upload coverage to Codecov
         if: always() && needs.changes.outputs.relevant == 'true'
-        uses: codecov/codecov-action@v5
+        uses: codecov/codecov-action@75cd11691c0faa626561e295848008c8a7dddffe 
# v5
         with:
           files: ./jacoco-report.xml
           disable_search: true
@@ -602,7 +602,7 @@ jobs:
         run: ./scripts/jacoco/generate_merged_coverage_report.sh 
$GITHUB_WORKSPACE
       - name: Upload coverage to Codecov
         if: always() && needs.changes.outputs.relevant == 'true'
-        uses: codecov/codecov-action@v5
+        uses: codecov/codecov-action@75cd11691c0faa626561e295848008c8a7dddffe 
# v5
         with:
           files: ./jacoco-report.xml
           disable_search: true
@@ -652,7 +652,7 @@ jobs:
         run: ./scripts/jacoco/generate_merged_coverage_report.sh 
$GITHUB_WORKSPACE
       - name: Upload coverage to Codecov
         if: always() && needs.changes.outputs.relevant == 'true'
-        uses: codecov/codecov-action@v5
+        uses: codecov/codecov-action@75cd11691c0faa626561e295848008c8a7dddffe 
# v5
         with:
           files: ./jacoco-report.xml
           disable_search: true
@@ -707,7 +707,7 @@ jobs:
         run: ./scripts/jacoco/generate_merged_coverage_report.sh 
$GITHUB_WORKSPACE
       - name: Upload coverage to Codecov
         if: always() && needs.changes.outputs.relevant == 'true'
-        uses: codecov/codecov-action@v5
+        uses: codecov/codecov-action@75cd11691c0faa626561e295848008c8a7dddffe 
# v5
         with:
           files: ./jacoco-report.xml
           disable_search: true
@@ -777,7 +777,7 @@ jobs:
         run: ./scripts/jacoco/generate_merged_coverage_report.sh 
$GITHUB_WORKSPACE
       - name: Upload coverage to Codecov
         if: always() && needs.changes.outputs.relevant == 'true'
-        uses: codecov/codecov-action@v5
+        uses: codecov/codecov-action@75cd11691c0faa626561e295848008c8a7dddffe 
# v5
         with:
           files: ./jacoco-report.xml
           disable_search: true
@@ -840,7 +840,7 @@ jobs:
         run: ./scripts/jacoco/generate_merged_coverage_report.sh 
$GITHUB_WORKSPACE
       - name: Upload coverage to Codecov
         if: always() && needs.changes.outputs.relevant == 'true'
-        uses: codecov/codecov-action@v5
+        uses: codecov/codecov-action@75cd11691c0faa626561e295848008c8a7dddffe 
# v5
         with:
           files: ./jacoco-report.xml
           disable_search: true
@@ -903,7 +903,7 @@ jobs:
         run: ./scripts/jacoco/generate_merged_coverage_report.sh 
$GITHUB_WORKSPACE
       - name: Upload coverage to Codecov
         if: always() && needs.changes.outputs.relevant == 'true'
-        uses: codecov/codecov-action@v5
+        uses: codecov/codecov-action@75cd11691c0faa626561e295848008c8a7dddffe 
# v5
         with:
           files: ./jacoco-report.xml
           disable_search: true
@@ -966,7 +966,7 @@ jobs:
         run: ./scripts/jacoco/generate_merged_coverage_report.sh 
$GITHUB_WORKSPACE
       - name: Upload coverage to Codecov
         if: always() && needs.changes.outputs.relevant == 'true'
-        uses: codecov/codecov-action@v5
+        uses: codecov/codecov-action@75cd11691c0faa626561e295848008c8a7dddffe 
# v5
         with:
           files: ./jacoco-report.xml
           disable_search: true
diff --git a/.github/workflows/pr_title_validation.yml 
b/.github/workflows/pr_title_validation.yml
index c9b2b1b277ec..5926843779f4 100644
--- a/.github/workflows/pr_title_validation.yml
+++ b/.github/workflows/pr_title_validation.yml
@@ -42,7 +42,7 @@ jobs:
 
       - name: Validate PR title with Conventional Commits spec
         if: steps.check-legacy-format.outputs.skip_conventional == 'false'
-        uses: amannn/action-semantic-pull-request@v6
+        uses: 
amannn/action-semantic-pull-request@48f256284bd46cdaab1048c3721360e808335d50 # 
v6
         env:
           GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
         with:

Reply via email to