Skip to content

Commit b05c371

Browse files
authored
[CVE-2023-30853] bump versions of gradle-build-action (#163)
1 parent b1ba7bc commit b05c371

File tree

4 files changed

+11
-11
lines changed

4 files changed

+11
-11
lines changed

.github/actions/gradle-build-and-publish/action.yaml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -30,24 +30,24 @@ runs:
3030
using: composite
3131
steps:
3232
- name: "Gradle: Build & Test"
33-
uses: gradle/gradle-build-action@v2
33+
uses: gradle/gradle-build-action@v2.9.0
3434
with:
3535
arguments: :${{ inputs.module }}:build
3636

3737
- name: "Gradle: Release Version"
3838
if: ${{ inputs.force_version == 'None' }}
39-
uses: gradle/gradle-build-action@v2
39+
uses: gradle/gradle-build-action@v2.9.0
4040
with:
4141
arguments: :${{ inputs.module }}:release
4242

4343
- name: "Gradle: Release Version (forced)"
4444
if: ${{ inputs.force_version != 'None' }}
45-
uses: gradle/gradle-build-action@v2
45+
uses: gradle/gradle-build-action@v2.9.0
4646
with:
4747
arguments: :${{ inputs.module }}:release -Prelease.forceVersion=${{ inputs.force_version }}
4848

4949
- name: "Gradle: Publish Artifacts"
50-
uses: gradle/gradle-build-action@v2
50+
uses: gradle/gradle-build-action@v2.9.0
5151
with:
5252
arguments: :${{ inputs.module }}:publish # publish to both S3 and Sonatype OSSRH
5353
env:

.github/workflows/github-main.yaml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -49,12 +49,12 @@ jobs:
4949
public: "true"
5050

5151
- name: "Gradle Build"
52-
uses: gradle/gradle-build-action@v2
52+
uses: gradle/gradle-build-action@v2.9.0
5353
with:
5454
arguments: build
5555

5656
- name: "Publish To S3"
57-
uses: gradle/gradle-build-action@v2
57+
uses: gradle/gradle-build-action@v2.9.0
5858
with:
5959
arguments: publishMavenJavaPublicationToS3Repository # publish only to S3
6060
if: github.ref == 'refs/heads/main'
@@ -68,7 +68,7 @@ jobs:
6868
uses: docker/setup-buildx-action@v2
6969

7070
- name: "Publish Images"
71-
uses: gradle/gradle-build-action@v2
71+
uses: gradle/gradle-build-action@v2.9.0
7272
with:
7373
arguments: pushCRD pushDockerMultiArch pushHelm -PdockerRegistry=${{ steps.login-ecr-public.outputs.public-registry }}/j8q9y0n6 -PhelmRegistry=${{ steps.login-ecr-public.outputs.public-registry }}/j8q9y0n6
7474
#if: github.ref == 'refs/heads/main'

.github/workflows/github-pr.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,7 @@ jobs:
4141
public: "true"
4242

4343
- name: "Setup Gradle"
44-
uses: gradle/gradle-build-action@v2
44+
uses: gradle/gradle-build-action@v2.9.0
4545

4646
- name: "Build & Test"
4747
run: ./gradlew build buildDocker

.github/workflows/github-publish.yaml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -74,15 +74,15 @@ jobs:
7474
uses: docker/setup-buildx-action@v2
7575

7676
- name: "Publish Operator Images"
77-
uses: gradle/gradle-build-action@v2
77+
uses: gradle/gradle-build-action@v2.9.0
7878
if: ${{ inputs.module == 'operator' }}
7979
with:
8080
arguments: operator:pushCRD operator:pushDockerMultiArch operator:pushHelm -PdockerRegistry=${{ steps.login-ecr-public.outputs.public-registry }}/j8q9y0n6 -PhelmRegistry=${{ steps.login-ecr-public.outputs.public-registry }}/j8q9y0n6
8181
env:
8282
ECR_REGISTRY: ${{ steps.login-ecr-public.outputs.public-registry }}
8383

8484
- name: "Publish Example Images"
85-
uses: gradle/gradle-build-action@v2
85+
uses: gradle/gradle-build-action@v2.9.0
8686
if: ${{ inputs.module == 'kafka-client' }}
8787
with:
8888
arguments: kafka-client-examples:simple-example:pushDockerMultiArch -PdockerRegistry=${{ steps.login-ecr-public.outputs.public-registry }}/j8q9y0n6 -PhelmRegistry=${{ steps.login-ecr-public.outputs.public-registry }}/j8q9y0n6
@@ -160,6 +160,6 @@ jobs:
160160
git push
161161
162162
- name: "Increment Version"
163-
uses: gradle/gradle-build-action@v2
163+
uses: gradle/gradle-build-action@v2.9.0
164164
with:
165165
arguments: :${{ inputs.module }}:markNextVersion -Prelease.incrementer=${{ inputs.increment }}

0 commit comments

Comments
 (0)