diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index d82f1f25..7f1ba411 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -28,14 +28,14 @@ jobs: uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 - name: Initialize CodeQL - uses: github/codeql-action/init@820e3160e279568db735cee8ed8f8e77a6da7818 # v3.32.6 + uses: github/codeql-action/init@603b797f8b14b413fe025cd935a91c16c4782713 # v3.33.0 with: languages: ${{ matrix.language }} - name: Autobuild - uses: github/codeql-action/autobuild@820e3160e279568db735cee8ed8f8e77a6da7818 # v3.32.6 + uses: github/codeql-action/autobuild@603b797f8b14b413fe025cd935a91c16c4782713 # v3.33.0 - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@820e3160e279568db735cee8ed8f8e77a6da7818 # v3.32.6 + uses: github/codeql-action/analyze@603b797f8b14b413fe025cd935a91c16c4782713 # v3.33.0 with: category: "/language:${{ matrix.language }}" \ No newline at end of file diff --git a/.github/workflows/docker-vulnerability-scan.yml b/.github/workflows/docker-vulnerability-scan.yml index bb71fd4b..db0cd3bb 100644 --- a/.github/workflows/docker-vulnerability-scan.yml +++ b/.github/workflows/docker-vulnerability-scan.yml @@ -28,7 +28,7 @@ jobs: - name: Login to Staging Amazon ECR id: login-ecr-staging - uses: aws-actions/amazon-ecr-login@cc05f4a4db45f6b446eee901ef3620a08754cbcf + uses: aws-actions/amazon-ecr-login@a6f26d4dac281724664e992240eebeb7469b9154 - name: Docker vulnerability scan uses: cds-snc/security-tools/.github/actions/docker-scan@5a93d1deec72d4cb2737cb8418364fedba1c695c # v3.2.1 diff --git a/.github/workflows/prod-docker-build-push.yml b/.github/workflows/prod-docker-build-push.yml index dd5f9270..11df0188 100644 --- a/.github/workflows/prod-docker-build-push.yml +++ b/.github/workflows/prod-docker-build-push.yml @@ -34,7 +34,7 @@ jobs: - name: Login to Amazon ECR id: login-ecr - uses: aws-actions/amazon-ecr-login@cc05f4a4db45f6b446eee901ef3620a08754cbcf + uses: aws-actions/amazon-ecr-login@a6f26d4dac281724664e992240eebeb7469b9154 - name: Tag images env: diff --git a/.github/workflows/staging-docker-build-push.yml b/.github/workflows/staging-docker-build-push.yml index 367cb9db..20713da1 100644 --- a/.github/workflows/staging-docker-build-push.yml +++ b/.github/workflows/staging-docker-build-push.yml @@ -37,7 +37,7 @@ jobs: - name: Login to Staging Amazon ECR id: login-ecr-staging - uses: aws-actions/amazon-ecr-login@cc05f4a4db45f6b446eee901ef3620a08754cbcf + uses: aws-actions/amazon-ecr-login@a6f26d4dac281724664e992240eebeb7469b9154 - name: Tag Images for Staging env: