diff --git a/.github/workflows/pin_deps.yml b/.github/workflows/pin_deps.yml index 3e24cdc4..23eb9036 100644 --- a/.github/workflows/pin_deps.yml +++ b/.github/workflows/pin_deps.yml @@ -88,7 +88,7 @@ jobs: pip install -r slsa_for_models/install/requirements_${{ matrix.os_family }}.txt pip list # For debugging - name: Upload freeze files - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4 + uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5 with: name: freeze-files-${{ matrix.os }} path: ./*/install/requirements*${{ matrix.os_family }}*txt diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index c787f1d7..c033d727 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -59,7 +59,7 @@ jobs: # Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF # format to the repository Actions tab. - name: "Upload artifact" - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4 + uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5 with: name: SARIF file path: results.sarif diff --git a/.github/workflows/slsa_for_ml.yml b/.github/workflows/slsa_for_ml.yml index a98261f0..b70219b5 100644 --- a/.github/workflows/slsa_for_ml.yml +++ b/.github/workflows/slsa_for_ml.yml @@ -67,7 +67,7 @@ jobs: python -m venv venv .github/workflows/scripts/venv_activate.sh python slsa_for_models/main.py "$MODEL_TYPE" - - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4 + - uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5 with: path: ${{ github.event.inputs.model_type || 'pytorch_jitted_model.pt' }} name: ${{ github.event.inputs.model_type || 'pytorch_jitted_model.pt' }}_${{ matrix.os_family }}