@@ -9,7 +9,7 @@ defaults:
99
1010env :
1111 # renovate: datasource=pypi depName=zizmor
12- ZIZMOR_VERSION : 1.15.2
12+ ZIZMOR_VERSION : 1.17.0
1313
1414on :
1515 workflow_call :
@@ -69,12 +69,12 @@ jobs:
6969 pull-requests : write
7070 steps :
7171 - name : Harden Runner
72- uses : step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
72+ uses : step-security/harden-runner@95d9a5deda9de15063e7595e9719c11c38c90ae2 # v2.13.2
7373 with :
7474 egress-policy : audit # change to 'egress-policy: block' after couple of runs
7575
7676 - name : Checkout Code
77- uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
77+ uses : actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1
7878 with :
7979 persist-credentials : false
8080
@@ -103,7 +103,7 @@ jobs:
103103
104104 - name : Upload MegaLinter scan results to GitHub Security tab
105105 if : ${{ always() }}
106- uses : github/codeql-action/upload-sarif@16140ae1a102900babc80a33c44059580f687047 # v4.30.9
106+ uses : github/codeql-action/upload-sarif@fdbfb4d2750291e159f0156def62b853c2798ca2 # v4.31.5
107107 with :
108108 sarif_file : " megalinter-reports/megalinter-report.sarif"
109109
@@ -117,11 +117,11 @@ jobs:
117117 contents : read
118118 steps :
119119 - name : Checkout Code
120- uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
120+ uses : actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1
121121 with :
122122 persist-credentials : false
123123 - name : Dependency Review
124- uses : actions/dependency-review-action@40c09b7dc99638e5ddb0bfd91c1673effc064d8a # v4.8.1
124+ uses : actions/dependency-review-action@3c4e3dcb1aa7874d2c16be7d79418e9b7efd6261 # v4.8.2
125125
126126 gradle-wrapper-validation :
127127 name : validate gradle wrapper
@@ -131,7 +131,7 @@ jobs:
131131 contents : read
132132 steps :
133133 - name : Checkout Code
134- uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
134+ uses : actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1
135135 with :
136136 persist-credentials : false
137137 - name : Validate Gradle Wrapper
@@ -145,7 +145,7 @@ jobs:
145145 contents : read
146146 steps :
147147 - name : Checkout Code
148- uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
148+ uses : actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1
149149 with :
150150 fetch-depth : 1
151151 persist-credentials : false
@@ -176,7 +176,7 @@ jobs:
176176 language : ${{ fromJSON(inputs.codeql-languages) }}
177177 steps :
178178 - name : Checkout Code
179- uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
179+ uses : actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1
180180 with :
181181 persist-credentials : false
182182
@@ -190,13 +190,13 @@ jobs:
190190
191191 - name : Set up .NET
192192 if : ${{ matrix.language == 'csharp' }}
193- uses : actions/setup-dotnet@d4c94342e560b34958eacfc5d055d21461ed1c5d # v5.0.0
193+ uses : actions/setup-dotnet@2016bd2012dba4e32de620c46fe006a3ac9f0602 # v5.0.1
194194 with :
195195 dotnet-version : ${{ inputs.dotnet-version }}
196196
197197 # Initializes the CodeQL tools for scanning.
198198 - name : Initialize CodeQL
199- uses : github/codeql-action/init@16140ae1a102900babc80a33c44059580f687047 # v4.30.9
199+ uses : github/codeql-action/init@fdbfb4d2750291e159f0156def62b853c2798ca2 # v4.31.5
200200 with :
201201 languages : ${{ matrix.language }}
202202 # If you wish to specify custom queries, you can do so here or in a config file.
@@ -209,7 +209,7 @@ jobs:
209209 # Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
210210 # If this step fails, then you should remove it and run the build manually (see below)
211211 - name : Autobuild
212- uses : github/codeql-action/autobuild@16140ae1a102900babc80a33c44059580f687047 # v4.30.9
212+ uses : github/codeql-action/autobuild@fdbfb4d2750291e159f0156def62b853c2798ca2 # v4.31.5
213213
214214 # ℹ️ Command-line programs to run using the OS shell.
215215 # 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun
@@ -222,7 +222,7 @@ jobs:
222222 # ./location_of_script_within_repo/buildscript.sh
223223
224224 - name : Perform CodeQL Analysis
225- uses : github/codeql-action/analyze@16140ae1a102900babc80a33c44059580f687047 # v4.30.9
225+ uses : github/codeql-action/analyze@fdbfb4d2750291e159f0156def62b853c2798ca2 # v4.31.5
226226 with :
227227 category : " /language:${{matrix.language}}"
228228
@@ -236,12 +236,12 @@ jobs:
236236 actions : read
237237 steps :
238238 - name : Checkout Code
239- uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
239+ uses : actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1
240240 with :
241241 persist-credentials : false
242242
243243 - name : Install the latest version of uv
244- uses : astral-sh/setup-uv@2ddd2b9cb38ad8efd50337e8ab201519a34c9f24 # v7.1.1
244+ uses : astral-sh/setup-uv@1e862dfacbd1d6d858c55d9b792c756523627244 # v7.1.4
245245 with :
246246 enable-cache : false
247247
@@ -262,7 +262,7 @@ jobs:
262262 ZIZMOR_CONFIG : /tmp/zizmor-standard-lint-defaults.yaml
263263
264264 - name : Upload SARIF file
265- uses : github/codeql-action/upload-sarif@16140ae1a102900babc80a33c44059580f687047 # v4.30.9
265+ uses : github/codeql-action/upload-sarif@fdbfb4d2750291e159f0156def62b853c2798ca2 # v4.31.5
266266 with :
267267 sarif_file : results.sarif
268268 category : zizmor
0 commit comments