File tree Expand file tree Collapse file tree 3 files changed +17
-6
lines changed
Expand file tree Collapse file tree 3 files changed +17
-6
lines changed Original file line number Diff line number Diff line change 1+ # To get started with Dependabot version updates, you'll need to specify which
2+ # package ecosystems to update and where the package manifests are located.
3+ # Please see the documentation for all configuration options:
4+ # https://docs.github.com/github/administering-a-repository/configuration-options-for-dependency-updates
5+
6+ version : 2
7+ updates :
8+ - package-ecosystem : " github-actions" # See documentation for possible values
9+ directory : " /" # Location of package manifests
10+ schedule :
11+ interval : " weekly"
Original file line number Diff line number Diff line change @@ -15,13 +15,13 @@ jobs:
1515 archive :
1616 runs-on : ubuntu-latest
1717 steps :
18- - uses : actions/checkout@v3
18+ - uses : actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
1919 - name : make dist
2020 run : |
2121 make dist
2222 version=`cat emscripten-version.txt | sed s/\"//g`
2323 echo "VERSION=$version" >> $GITHUB_ENV
24- - uses : actions/upload-artifact@v3
24+ - uses : actions/upload-artifact@0b7f8abb1508181956e8e162db84b466c27e18ce # v3.1.2
2525 with :
2626 name : emscripten-${{ env.VERSION }}
2727 path : emscripten-${{ env.VERSION }}.tar.bz2
Original file line number Diff line number Diff line change @@ -22,12 +22,12 @@ jobs:
2222
2323 steps :
2424 - name : " Checkout code"
25- uses : actions/checkout@a12a3943b4bdde767164f792f33f40b04645d846 # tag= v3.0.0
25+ uses : actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
2626 with :
2727 persist-credentials : false
2828
2929 - name : " Run analysis"
30- uses : ossf/scorecard-action@3e15ea8318eee9b333819ec77a36aca8d39df13e # tag=v1 .1.1
30+ uses : ossf/scorecard-action@80e868c13c90f172d68d1f4501dee99e2479f7af # v2 .1.3
3131 with :
3232 results_file : results.sarif
3333 results_format : sarif
@@ -42,14 +42,14 @@ jobs:
4242
4343 # Upload the results as artifacts (optional).
4444 - name : " Upload artifact"
45- uses : actions/upload-artifact@6673cd052c4cd6fcf4b4e6e60ea986c889389535 # tag= v3.0.0
45+ uses : actions/upload-artifact@0b7f8abb1508181956e8e162db84b466c27e18ce # v3.1.2
4646 with :
4747 name : SARIF file
4848 path : results.sarif
4949 retention-days : 5
5050
5151 # Upload the results to GitHub's code scanning dashboard.
5252 - name : " Upload to code-scanning"
53- uses : github/codeql-action/upload-sarif@5f532563584d71fdef14ee64d17bafb34f751ce5 # tag=v1.0.26
53+ uses : github/codeql-action/upload-sarif@6c089f53dd51dc3fc7e599c3cb5356453a52ca9e # v2.20.0
5454 with :
5555 sarif_file : results.sarif
You can’t perform that action at this time.
0 commit comments