diff --git a/.github/workflows/periodic-zizmor.yaml b/.github/workflows/periodic-zizmor.yaml index 864ace0..231493e 100644 --- a/.github/workflows/periodic-zizmor.yaml +++ b/.github/workflows/periodic-zizmor.yaml @@ -36,7 +36,7 @@ jobs: steps: - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@v5 with: persist-credentials: false @@ -58,7 +58,7 @@ jobs: ${{ matrix.repository.repo }} - name: Checkout Target - uses: actions/checkout@v4 + uses: actions/checkout@v5 with: repository: ${{ matrix.repository.owner }}/${{ matrix.repository.repo }} token: ${{ steps.get-token.outputs.token }} diff --git a/.github/workflows/self-zizmor.yaml b/.github/workflows/self-zizmor.yaml index 6a15a76..346b0eb 100644 --- a/.github/workflows/self-zizmor.yaml +++ b/.github/workflows/self-zizmor.yaml @@ -16,7 +16,7 @@ jobs: found-files: ${{ steps.zizmor-check.outputs.found-files }} steps: - name: Checkout - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 + uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5 - name: Run zizmor id: zizmor-check shell: bash diff --git a/.github/workflows/snyk_monitor.yml b/.github/workflows/snyk_monitor.yml index e632e05..4c99607 100644 --- a/.github/workflows/snyk_monitor.yml +++ b/.github/workflows/snyk_monitor.yml @@ -10,7 +10,7 @@ jobs: runs-on: ubuntu-latest steps: - - uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab # v3 + - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5 with: persist-credentials: false - name: Run Snyk to import ${{ github.event.repository.name }} to Snyk diff --git a/trivy/action.yml b/trivy/action.yml index 2295785..ccd702e 100644 --- a/trivy/action.yml +++ b/trivy/action.yml @@ -13,12 +13,12 @@ runs: using: "composite" steps: - name: "Checkout Repository" - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # 4.2.2 + uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # 5.0.0 with: fetch-depth: 0 - name: "Checkout Target Branch" - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # 4.2.2 + uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # 5.0.0 with: ref: ${{ github.base_ref }} @@ -37,7 +37,7 @@ runs: severity: ${{ inputs.severities }} - name: Checkout current commit - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # 4.2.2 + uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # 5.0.0 with: ref: ${{ github.sha }} clean: false