Skip to content

Commit 8f38bcc

Browse files
committed
Add ghasum, update dirty-waters action
1 parent 587f514 commit 8f38bcc

File tree

2 files changed

+15
-6
lines changed

2 files changed

+15
-6
lines changed

.github/workflows/code-qualitiy.yml

Lines changed: 8 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -106,20 +106,25 @@ jobs:
106106
pull-requests: write # To comment on a Pull Request
107107
steps:
108108
- name: Harden Runner
109-
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
109+
uses: step-security/harden-runner@0634a2670c59f64b4a01f0f96f84700a4088b9f0 # v2.12.0
110110
with:
111111
egress-policy: audit
112112

113113
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
114114
with:
115115
submodules: true
116+
117+
- name: Verify action checksums
118+
uses: ./.github/actions/ghasum
119+
116120
- name: Setup JDK17
117-
uses: actions/setup-java@3a4f6e1af504cf6a31855fa899c6aa5355ba6c12 # v4.7.0
121+
uses: actions/[email protected].1
118122
with:
119123
java-version: '17'
120124
distribution: 'temurin'
125+
121126
- name: Dirty Waters Analysis
122-
uses: chains-project/dirty-waters-action@57e2b7be964e687bdab629460efb274053fe3b28 # v1.11.45
127+
uses: chains-project/[email protected].48
123128
with:
124129
github_token: ${{ secrets.GITHUB_TOKEN }}
125130
package_manager: maven

.github/workflows/gha.sum

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -5,10 +5,14 @@ actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 aYx2ZNrV/U9daVa5XJLnuR
55
actions/dependency-review-action@bc41886e18ea39df68b1b1245f4184881938e050 Gd1O6ZG0JtkpyKVsxOwIuNtshdlcYheIADUYdNOIOjo=
66
actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 vSiNC7HetrtPF3QhZDzPHWyJ1e8pFltzruLjcw65Sok=
77
actions/setup-java@387ac29b308b003ca37ba93a6cab5eb57c8f5f93 XE1eqHfEOlHsHx+3cUQA1OGC3jxGBnmx7eTIdEzwSoI=
8-
actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 cKZQn6p38RgADB4MCMpbFp94sScgm/u3B7rEDB9QS5I=
8+
actions/[email protected] cKZQn6p38RgADB4MCMpbFp94sScgm/u3B7rEDB9QS5I=
9+
actions/[email protected] MTHBGEHwb+MeIw3xRLiVuM/uyRfuK8hlVXL+Z/yEA8c=
910
actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 kZHHfo2NsxevBRTKrZnUpDu0Cxgtj5Vooe4x4rylvg8=
10-
github/codeql-action@96f518a34f7a870018057716cc4d7a5c014bd61c h0CGAC50uRuMQV8hj6pLuc5zMsaXvXYE/35vEhbnEbs=
11-
jreleaser/release-action@f69e545b05f149483cecb2fb81866247992694b8 Ixc/05XDYYHGUvtC6Jt9gB/mpHPIwBX7PR8At1yEWSs=
11+
actions/[email protected] kZHHfo2NsxevBRTKrZnUpDu0Cxgtj5Vooe4x4rylvg8=
12+
github/codeql-action@d6bbdef45e766d081b84a2def353b0055f728d3e a64qKQusITtfuxl3BMjHFBq/jN7uTJqDLVTWW80ij+s=
13+
github/[email protected] a64qKQusITtfuxl3BMjHFBq/jN7uTJqDLVTWW80ij+s=
14+
chains-project/[email protected] BlbW87cG7BWyVwIVCVZ404lqjY7rTn4kW8qvMsJMUTw=
15+
jreleaser/[email protected] Ixc/05XDYYHGUvtC6Jt9gB/mpHPIwBX7PR8At1yEWSs=
1216
ossf/scorecard-action@05b42c624433fc40578a4040d5cf5e36ddca8cde NlVzVIaycy3fhYp7tgiwvpWvzSsPa48uTVejF6tHEog=
1317
stefanzweifel/git-auto-commit-action@778341af668090896ca464160c2def5d1d1a3eb0 5+Y5J+dG+VvtR13IIYuBHcAdJAcnDBQU/U0sRO3YZZw=
1418
step-security/harden-runner@ec9f2d5744a09debf3a187a3f4f675c53b671911 rG/FhhPP4VlsNB/2lKudn7rieQAYYNLIRb34q19qmFU=

0 commit comments

Comments
 (0)