diff --git a/.github/workflows/python-bindings.yml b/.github/workflows/python-bindings.yml index 0c7f1e4..94b4743 100644 --- a/.github/workflows/python-bindings.yml +++ b/.github/workflows/python-bindings.yml @@ -22,10 +22,10 @@ jobs: contents: read steps: - - uses: actions/checkout@v7 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Cache build dependencies - uses: actions/cache@v6 + uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 env: cache-name: makefile-deps with: @@ -35,7 +35,7 @@ jobs: ${{ runner.os }}-${{ env.cache-name }}-${{ hashFiles('Makefile') }} ${{ runner.os }}-${{ env.cache-name }}- - - uses: actions/setup-python@v6 + - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: '3.12' @@ -80,14 +80,14 @@ jobs: run: python -m twine check dist/* - name: Publish to PyPI - if: github.event_name != 'pull_request' && needs.ci_checks.outputs.publish_release == 'true' - uses: pypa/gh-action-pypi-publish@release/v1 + if: github.ref == 'refs/heads/main' || needs.ci_checks.outputs.publish_release == 'true' + uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1.14.2 with: packages-dir: bindings/python/dist - name: Upload build artifact - if: needs.ci_checks.outputs.publish_release != 'true' - uses: actions/upload-artifact@v4 + if: github.ref != 'refs/heads/main' && needs.ci_checks.outputs.publish_release != 'true' + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: python-bindings-dist path: bindings/python/dist/*