diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index c0de372..3b004d1 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -12,7 +12,7 @@ permissions: read-all jobs: build: - uses: chgl/.github/.github/workflows/standard-build.yaml@162c01b19aa71d96483ecdcda74d4993121bff1f # v1.9.1 + uses: chgl/.github/.github/workflows/standard-build.yaml@a38e8e9126feb23f142243b3ffa761d88e4ce23a # v1.10.0 permissions: contents: write id-token: write @@ -27,7 +27,7 @@ jobs: github-token: ${{ secrets.GITHUB_TOKEN }} lint: - uses: chgl/.github/.github/workflows/standard-lint.yaml@162c01b19aa71d96483ecdcda74d4993121bff1f # v1.9.1 + uses: chgl/.github/.github/workflows/standard-lint.yaml@a38e8e9126feb23f142243b3ffa761d88e4ce23a # v1.10.0 permissions: contents: read pull-requests: write @@ -42,7 +42,7 @@ jobs: github-token: ${{ secrets.GITHUB_TOKEN }} release: - uses: chgl/.github/.github/workflows/standard-release.yaml@162c01b19aa71d96483ecdcda74d4993121bff1f # v1.9.1 + uses: chgl/.github/.github/workflows/standard-release.yaml@a38e8e9126feb23f142243b3ffa761d88e4ce23a # v1.10.0 needs: - build permissions: diff --git a/.github/workflows/daily-trivy-scan.yaml b/.github/workflows/daily-trivy-scan.yaml index 9b1a6fe..8bad584 100644 --- a/.github/workflows/daily-trivy-scan.yaml +++ b/.github/workflows/daily-trivy-scan.yaml @@ -23,6 +23,6 @@ jobs: severity: "CRITICAL,HIGH" - name: Upload Trivy scan results to GitHub Security tab - uses: github/codeql-action/upload-sarif@f09c1c0a94de965c15400f5634aa42fac8fb8f88 # v3.27.5 + uses: github/codeql-action/upload-sarif@df409f7d9260372bd5f19e5b04e83cb3c43714ae # v3.27.9 with: sarif_file: "trivy-results.sarif" diff --git a/.github/workflows/scorecards.yml b/.github/workflows/scorecards.yml index f4b1e28..1d1bf68 100644 --- a/.github/workflows/scorecards.yml +++ b/.github/workflows/scorecards.yml @@ -67,6 +67,6 @@ jobs: # Upload the results to GitHub's code scanning dashboard. - name: "Upload to code-scanning" - uses: github/codeql-action/upload-sarif@f09c1c0a94de965c15400f5634aa42fac8fb8f88 # v3.27.5 + uses: github/codeql-action/upload-sarif@df409f7d9260372bd5f19e5b04e83cb3c43714ae # v3.27.9 with: sarif_file: results.sarif