File tree 3 files changed +5
-5
lines changed
3 files changed +5
-5
lines changed Original file line number Diff line number Diff line change @@ -25,16 +25,16 @@ jobs:
25
25
run : git config --global --add safe.directory "$GITHUB_WORKSPACE"
26
26
27
27
- name : Initialize CodeQL
28
- uses : github/codeql-action/init@v3
28
+ uses : github/codeql-action/init@df409f7d9260372bd5f19e5b04e83cb3c43714ae # v3.27.9
29
29
with :
30
30
languages : go
31
31
# Details on CodeQL's query packs refer to : https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning#using-queries-in-ql-packs
32
32
queries : +security-and-quality
33
33
34
34
- name : Autobuild
35
- uses : github/codeql-action/autobuild@v3
35
+ uses : github/codeql-action/autobuild@df409f7d9260372bd5f19e5b04e83cb3c43714ae # v3.27.9
36
36
37
37
- name : Perform CodeQL Analysis
38
- uses : github/codeql-action/analyze@v3
38
+ uses : github/codeql-action/analyze@df409f7d9260372bd5f19e5b04e83cb3c43714ae # v3.27.9
39
39
with :
40
40
category : " /language:go"
Original file line number Diff line number Diff line change 35
35
SEMGREP_APP_TOKEN : ${{ secrets.SEMGREP_APP_TOKEN }}
36
36
37
37
- name : Upload SARIF file for GitHub Advanced Security Dashboard
38
- uses : github/codeql-action/upload-sarif@v3
38
+ uses : github/codeql-action/upload-sarif@df409f7d9260372bd5f19e5b04e83cb3c43714ae # v3.27.9
39
39
with :
40
40
sarif_file : semgrep.sarif
41
41
if : ${{ github.event.number == '' && !cancelled() }}
Original file line number Diff line number Diff line change 56
56
trivy-config : trivy.yml
57
57
58
58
- name : Upload Trivy scan results to GitHub Security tab
59
- uses : github/codeql-action/upload-sarif@v3
59
+ uses : github/codeql-action/upload-sarif@df409f7d9260372bd5f19e5b04e83cb3c43714ae # v3.27.9
60
60
if : ${{ inputs.publish }}
61
61
with :
62
62
sarif_file : ${{ inputs.output }}
You can’t perform that action at this time.
0 commit comments