File tree Expand file tree Collapse file tree 6 files changed +7
-7
lines changed
Expand file tree Collapse file tree 6 files changed +7
-7
lines changed Original file line number Diff line number Diff line change 5757
5858 # Initializes the CodeQL tools for scanning.
5959 - name : Initialize CodeQL
60- uses : github/codeql-action/init@0499de31b99561a6d14a36a5f662c2a54f91beee # v4.31.2
60+ uses : github/codeql-action/init@5d4e8d1aca955e8d8589aabd499c5cae939e33c7 # v4.31.9
6161 with :
6262 languages : ${{ matrix.language }}
6363 build-mode : ${{ matrix.build-mode }}
6969 # queries: security-extended,security-and-quality
7070
7171 - name : Perform CodeQL Analysis
72- uses : github/codeql-action/analyze@0499de31b99561a6d14a36a5f662c2a54f91beee # v4.31.2
72+ uses : github/codeql-action/analyze@5d4e8d1aca955e8d8589aabd499c5cae939e33c7 # v4.31.9
7373 with :
7474 category : " /language:${{matrix.language}}"
Original file line number Diff line number Diff line change 3737 with :
3838 should-scan-archives : true
3939 - name : Upload DevSkim scan results to GitHub Security tab
40- uses : github/codeql-action/upload-sarif@0499de31b99561a6d14a36a5f662c2a54f91beee # v4.31.2
40+ uses : github/codeql-action/upload-sarif@5d4e8d1aca955e8d8589aabd499c5cae939e33c7 # v4.31.9
4141 with :
4242 sarif_file : devskim-results.sarif
Original file line number Diff line number Diff line change 4848 - if : github.ref == 'refs/heads/alpine'
4949 uses : sigstore/cosign-installer@faadad0cce49287aee09b3a48701e75088a2c6ad # v4.0.0
5050 - uses : docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130 # v3.7.0
51- - uses : docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
51+ - uses : docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0
5252 - uses : docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5.10.0
5353 id : meta
5454 with :
Original file line number Diff line number Diff line change 4444 echo "SOURCE_DATE_EPOCH=$(git log -1 --pretty=%ct)" >> "${GITHUB_ENV}"
4545 - uses : sigstore/cosign-installer@faadad0cce49287aee09b3a48701e75088a2c6ad # v4.0.0
4646 - uses : docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130 # v3.7.0
47- - uses : docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
47+ - uses : docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0
4848 - uses : docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5.10.0
4949 id : meta
5050 with :
Original file line number Diff line number Diff line change 3434 id : scan
3535 uses : microsoft/security-devops-action@08976cb623803b1b36d7112d4ff9f59eae704de0 # v1.12.0
3636 - name : Upload MSDO scan results to GitHub Security tab
37- uses : github/codeql-action/upload-sarif@0499de31b99561a6d14a36a5f662c2a54f91beee # v4.31.2
37+ uses : github/codeql-action/upload-sarif@5d4e8d1aca955e8d8589aabd499c5cae939e33c7 # v4.31.9
3838 with :
3939 sarif_file : ${{ steps.scan.outputs.sarifFile }}
Original file line number Diff line number Diff line change 3737 results_format : sarif
3838 publish_results : true
3939 - name : " Upload to code-scanning"
40- uses : github/codeql-action/upload-sarif@0499de31b99561a6d14a36a5f662c2a54f91beee # v4.31.2
40+ uses : github/codeql-action/upload-sarif@5d4e8d1aca955e8d8589aabd499c5cae939e33c7 # v4.31.9
4141 with :
4242 sarif_file : scorecards-results.sarif
You can’t perform that action at this time.
0 commit comments