diff --git a/.github/workflows/yocto-build-deploy.yml b/.github/workflows/yocto-build-deploy.yml index c6100cba7..071168c7a 100644 --- a/.github/workflows/yocto-build-deploy.yml +++ b/.github/workflows/yocto-build-deploy.yml @@ -258,7 +258,7 @@ jobs: # https://github.com/actions/checkout - name: Clone device repository - uses: actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 # v4.2.0 + uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1 with: repository: ${{ inputs.device-repo }} token: ${{ steps.app-token.outputs.token || secrets.GITHUB_TOKEN }} @@ -389,7 +389,7 @@ jobs: echo "is_private=${is_private}" >>"${GITHUB_OUTPUT}" - name: Checkout private Contracts - uses: actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 # v4.2.0 + uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1 if: steps.balena-lib.outputs.is_private == 'true' with: repository: balena-io/private-contracts @@ -1106,7 +1106,7 @@ jobs: # Clone the device respository to fetch Leviathan # https://github.com/actions/checkout - name: Clone device repository - uses: actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 # v4.2.0 + uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1 with: repository: ${{ inputs.device-repo }} token: ${{ steps.app-token.outputs.token || secrets.GITHUB_TOKEN }} @@ -1160,7 +1160,7 @@ jobs: # Check out private contracts if this is a private device type - as these are required for the tests - name: Checkout private Contracts - uses: actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 # v4.2.0 + uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1 if: needs.build.outputs.is_private == 'true' with: repository: balena-io/private-contracts