diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index ff22287..3d2a392 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -52,7 +52,7 @@ jobs: # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL - uses: github/codeql-action/init@e4b846c482eb8fdb860c7c61d2eb64f9bdf79420 + uses: github/codeql-action/init@f13b180fb88fab31693634cb19e73cb3ed1cb7d8 with: languages: ${{ matrix.language }} queries: +security-and-quality @@ -64,7 +64,7 @@ jobs: # Autobuild attempts to build any compiled languages (C/C++, C#, or Java). # If this step fails, then you should remove it and run the build manually (see below) - name: Autobuild - uses: github/codeql-action/autobuild@e4b846c482eb8fdb860c7c61d2eb64f9bdf79420 + uses: github/codeql-action/autobuild@f13b180fb88fab31693634cb19e73cb3ed1cb7d8 # â„šī¸ Command-line programs to run using the OS shell. # 📚 https://git.io/JvXDl @@ -78,4 +78,4 @@ jobs: # make release - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@e4b846c482eb8fdb860c7c61d2eb64f9bdf79420 + uses: github/codeql-action/analyze@f13b180fb88fab31693634cb19e73cb3ed1cb7d8 diff --git a/.github/workflows/devskim-analysis.yml b/.github/workflows/devskim-analysis.yml index e6d0668..592120e 100644 --- a/.github/workflows/devskim-analysis.yml +++ b/.github/workflows/devskim-analysis.yml @@ -39,6 +39,6 @@ jobs: uses: microsoft/DevSkim-Action@a8a9e06bab570db990fe7351ae9d4d444b9489ca - name: Upload DevSkim scan results to GitHub Security tab - uses: github/codeql-action/upload-sarif@e4b846c482eb8fdb860c7c61d2eb64f9bdf79420 + uses: github/codeql-action/upload-sarif@f13b180fb88fab31693634cb19e73cb3ed1cb7d8 with: sarif_file: devskim-results.sarif diff --git a/.github/workflows/ossar-analysis.yml b/.github/workflows/ossar-analysis.yml index 3572022..0bf1443 100644 --- a/.github/workflows/ossar-analysis.yml +++ b/.github/workflows/ossar-analysis.yml @@ -57,6 +57,6 @@ jobs: # Upload results to the Security tab - name: Upload OSSAR results - uses: github/codeql-action/upload-sarif@e4b846c482eb8fdb860c7c61d2eb64f9bdf79420 + uses: github/codeql-action/upload-sarif@f13b180fb88fab31693634cb19e73cb3ed1cb7d8 with: sarif_file: ${{ steps.ossar.outputs.sarifFile }} diff --git a/.github/workflows/scorecards-analysis.yml b/.github/workflows/scorecards-analysis.yml index 5a904f4..6de44f6 100644 --- a/.github/workflows/scorecards-analysis.yml +++ b/.github/workflows/scorecards-analysis.yml @@ -57,6 +57,6 @@ jobs: # Upload the results to GitHub's code scanning dashboard. - name: "Upload to code-scanning" - uses: github/codeql-action/upload-sarif@e4b846c482eb8fdb860c7c61d2eb64f9bdf79420 + uses: github/codeql-action/upload-sarif@f13b180fb88fab31693634cb19e73cb3ed1cb7d8 with: sarif_file: results.sarif diff --git a/.github/workflows/shiftleft-analysis.yml b/.github/workflows/shiftleft-analysis.yml index 48048cb..1fc53a3 100644 --- a/.github/workflows/shiftleft-analysis.yml +++ b/.github/workflows/shiftleft-analysis.yml @@ -55,6 +55,6 @@ jobs: # type: python - name: Upload report - uses: github/codeql-action/upload-sarif@e4b846c482eb8fdb860c7c61d2eb64f9bdf79420 + uses: github/codeql-action/upload-sarif@f13b180fb88fab31693634cb19e73cb3ed1cb7d8 with: sarif_file: reports