# Pinned versions of the CI linters installed by install-ci-tools.sh. # Renovate keeps these up to date (see customManagers in renovate/renovate.json). # # Every version below matches what was already installed on the runner, so # pinning them changes what CI does not at all. It changes what CI does when # the runner is rebuilt with something else: today install-ci-tools.sh finds # the pinned version already on PATH and installs nothing, and a runner that # drifts gets the pinned one installed over it. # # The renovate image version is NOT pinned here: renovate/k8s/cronjob.yaml is the # single source of truth and the workflows read the tag from it, so there is # nothing to drift. ACTIONLINT_VERSION="1.7.7" SHELLCHECK_VERSION="0.11.0" KUBECONFORM_VERSION="0.8.0" PRETTIER_VERSION="3.8.1" RUFF_VERSION="0.16.8" YAMLLINT_VERSION="1.38.0" HADOLINT_VERSION="2.14.0" # pip-audit reads the advisory database over the network, so a floating version # would make the same commit report different things on different days. Pin it # like the rest: the advisories themselves are the moving part, not the tool. PIP_AUDIT_VERSION="2.10.1" # uv builds the throwaway venv the pytest job runs in, and unpacks the PyPI # wheels for ruff, yamllint and pip-audit. UV_VERSION="0.12.17"