@@ -13,13 +13,13 @@ jobs:
1313 timeout-minutes : 1
1414 steps :
1515 - name : Checkout repository
16- uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
16+ uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
1717 with :
1818 persist-credentials : false
1919
2020 # https://github.com/rhysd/actionlint
2121 - name : Run actionlint
22- uses : docker://rhysd/actionlint:1.7.6
22+ uses : docker://rhysd/actionlint:1.7.7
2323 with :
2424 args : " -color -verbose"
2525
@@ -33,18 +33,18 @@ jobs:
3333 timeout-minutes : 10
3434 steps :
3535 - name : Checkout code
36- uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
36+ uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
3737 with :
3838 persist-credentials : false
3939
4040 - name : Run octoscan
4141 id : octoscan
42- uses : synacktiv/action-octoscan@6b1cf2343893dfb9e5f75652388bd2dc83f456b0 # v1
42+ uses : synacktiv/action-octoscan@6b1cf2343893dfb9e5f75652388bd2dc83f456b0 # v1.0.0
4343 with :
4444 filter_triggers : ' '
4545
4646 - name : Upload SARIF file
47- uses : github/codeql-action/upload-sarif@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 # v3
47+ uses : github/codeql-action/upload-sarif@b6a472f63d85b9c78a3ac5e89422239fc15e9b3c # v3.28.1
4848 with :
4949 sarif_file : ${{steps.octoscan.outputs.sarif_output}}
5050 category : octoscan
@@ -58,21 +58,21 @@ jobs:
5858 contents : read
5959 steps :
6060 - name : Checkout repository
61- uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
61+ uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
6262 with :
6363 persist-credentials : false
6464
6565 - name : Install the latest version of uv
66- uses : astral-sh/setup-uv@38f3f104447c67c051c4a08e39b64a148898af3a # v4
66+ uses : astral-sh/setup-uv@b5f58b2abc5763ade55e4e9d0fe52cd1ff7979ca # v5.2.1
6767
6868 # https://github.com/woodruffw/zizmor
6969 - name : Run zizmor
70- run : uvx zizmor@1.1.1 --format sarif . > results.sarif
70+ run : uvx zizmor@1.2.2 --format sarif . > results.sarif
7171 env :
7272 GH_TOKEN : ${{ secrets.GITHUB_TOKEN }}
7373
7474 - name : Upload SARIF file
75- uses : github/codeql-action/upload-sarif@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 # v3
75+ uses : github/codeql-action/upload-sarif@b6a472f63d85b9c78a3ac5e89422239fc15e9b3c # v3.28.1
7676 with :
7777 sarif_file : results.sarif
7878 category : zizmor
@@ -85,15 +85,15 @@ jobs:
8585 contents : read
8686 steps :
8787 - name : Checkout repository
88- uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
88+ uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
8989 with :
9090 persist-credentials : false
9191
9292 - name : Run Poutine
9393 uses : boostsecurityio/poutine-action@84c0a0d32e8d57ae12651222be1eb15351429228 # v0.15.2
9494
9595 - name : Upload SARIF file
96- uses : github/codeql-action/upload-sarif@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 # v3
96+ uses : github/codeql-action/upload-sarif@b6a472f63d85b9c78a3ac5e89422239fc15e9b3c # v3.28.1
9797 with :
9898 sarif_file : results.sarif
9999 category : poutine
0 commit comments