@@ -233,7 +233,7 @@ jobs:
233233 # Uses custom configuration for enhanced security coverage.
234234 # The config file specifies both security-extended and security-and-quality query suites.
235235 - name : Initialize CodeQL
236- uses : github/codeql-action/init@fe4161a26a8629af62121b670040955b330f9af2 # v4.31.6
236+ uses : github/codeql-action/init@cf1bb45a277cb3c205638b2cd5c984db1c46a412 # v4.31.7
237237 with :
238238 languages : ${{ matrix.language }}
239239 config-file : ./.github/codeql/codeql-config.yml
@@ -253,7 +253,7 @@ jobs:
253253 # Results can be viewed in the Security > Code scanning alerts tab
254254 - name : Perform CodeQL Analysis
255255 id : analyze
256- uses : github/codeql-action/analyze@fe4161a26a8629af62121b670040955b330f9af2 # v4.31.6
256+ uses : github/codeql-action/analyze@cf1bb45a277cb3c205638b2cd5c984db1c46a412 # v4.31.7
257257 with :
258258 category : " /language:${{matrix.language}}" # Categorize results by language
259259 upload : true # Upload SARIF results to GitHub Security tab
@@ -325,7 +325,7 @@ jobs:
325325 # Upload Trivy results to GitHub Security tab
326326 # Always runs even if scan fails, to ensure visibility
327327 - name : Upload Trivy results to GitHub Security
328- uses : github/codeql-action/upload-sarif@fe4161a26a8629af62121b670040955b330f9af2 # v4.31.6
328+ uses : github/codeql-action/upload-sarif@cf1bb45a277cb3c205638b2cd5c984db1c46a412 # v4.31.7
329329 if : always() # Upload even if scan found vulnerabilities
330330 with :
331331 sarif_file : ' trivy-results.sarif'
@@ -498,7 +498,7 @@ jobs:
498498 # Upload Scorecard results to GitHub Security tab
499499 # Always uploads to track score trends over time
500500 - name : Upload Scorecard results to GitHub Security
501- uses : github/codeql-action/upload-sarif@fe4161a26a8629af62121b670040955b330f9af2 # v4.31.6
501+ uses : github/codeql-action/upload-sarif@cf1bb45a277cb3c205638b2cd5c984db1c46a412 # v4.31.7
502502 if : always() # Upload even if score is below threshold
503503 with :
504504 sarif_file : scorecard-results.sarif
0 commit comments