Skip to content

Commit 9cf068a

Browse files
deps: Update GitHub Actions
1 parent 5ba3c18 commit 9cf068a

File tree

2 files changed

+5
-5
lines changed

2 files changed

+5
-5
lines changed

.github/workflows/ci.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -133,7 +133,7 @@ jobs:
133133
echo '```' >> $GITHUB_STEP_SUMMARY
134134
135135
- name: Upload coverage to Codecov
136-
uses: codecov/codecov-action@5a1091511ad55cbe89839c7260b706298ca349f7 # v5.5.1
136+
uses: codecov/codecov-action@671740ac38dd9b0130fbe1cec585b89eea48d3de # v5.5.2
137137
with:
138138
token: ${{ secrets.CODECOV_TOKEN }}
139139
slug: VirtualAgentics/review-bot-automator

.github/workflows/security.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -233,7 +233,7 @@ jobs:
233233
# Uses custom configuration for enhanced security coverage.
234234
# The config file specifies both security-extended and security-and-quality query suites.
235235
- name: Initialize CodeQL
236-
uses: github/codeql-action/init@fe4161a26a8629af62121b670040955b330f9af2 # v4.31.6
236+
uses: github/codeql-action/init@cf1bb45a277cb3c205638b2cd5c984db1c46a412 # v4.31.7
237237
with:
238238
languages: ${{ matrix.language }}
239239
config-file: ./.github/codeql/codeql-config.yml
@@ -253,7 +253,7 @@ jobs:
253253
# Results can be viewed in the Security > Code scanning alerts tab
254254
- name: Perform CodeQL Analysis
255255
id: analyze
256-
uses: github/codeql-action/analyze@fe4161a26a8629af62121b670040955b330f9af2 # v4.31.6
256+
uses: github/codeql-action/analyze@cf1bb45a277cb3c205638b2cd5c984db1c46a412 # v4.31.7
257257
with:
258258
category: "/language:${{matrix.language}}" # Categorize results by language
259259
upload: true # Upload SARIF results to GitHub Security tab
@@ -325,7 +325,7 @@ jobs:
325325
# Upload Trivy results to GitHub Security tab
326326
# Always runs even if scan fails, to ensure visibility
327327
- name: Upload Trivy results to GitHub Security
328-
uses: github/codeql-action/upload-sarif@fe4161a26a8629af62121b670040955b330f9af2 # v4.31.6
328+
uses: github/codeql-action/upload-sarif@cf1bb45a277cb3c205638b2cd5c984db1c46a412 # v4.31.7
329329
if: always() # Upload even if scan found vulnerabilities
330330
with:
331331
sarif_file: 'trivy-results.sarif'
@@ -498,7 +498,7 @@ jobs:
498498
# Upload Scorecard results to GitHub Security tab
499499
# Always uploads to track score trends over time
500500
- name: Upload Scorecard results to GitHub Security
501-
uses: github/codeql-action/upload-sarif@fe4161a26a8629af62121b670040955b330f9af2 # v4.31.6
501+
uses: github/codeql-action/upload-sarif@cf1bb45a277cb3c205638b2cd5c984db1c46a412 # v4.31.7
502502
if: always() # Upload even if score is below threshold
503503
with:
504504
sarif_file: scorecard-results.sarif

0 commit comments

Comments
 (0)