diff --git a/.github/workflows/security-codeql.yml b/.github/workflows/security-codeql.yml index cd312d0b1e..1a9267a119 100644 --- a/.github/workflows/security-codeql.yml +++ b/.github/workflows/security-codeql.yml @@ -44,7 +44,7 @@ jobs: disable-cache: 'true' - name: Initialize CodeQL - uses: github/codeql-action/init@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v4.36.0 + uses: github/codeql-action/init@87557b9c84dde89fdd9b10e88954ac2f4248e463 # v4.36.1 with: languages: ${{ matrix.language }} build-mode: ${{ matrix.build-mode }} @@ -54,6 +54,6 @@ jobs: run: ./gradlew assemble --no-daemon - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v4.36.0 + uses: github/codeql-action/analyze@87557b9c84dde89fdd9b10e88954ac2f4248e463 # v4.36.1 with: category: "/language:${{ matrix.language }}" diff --git a/.github/workflows/security-fluidscan.yml b/.github/workflows/security-fluidscan.yml index 91d917fbbd..dc0dd963ec 100644 --- a/.github/workflows/security-fluidscan.yml +++ b/.github/workflows/security-fluidscan.yml @@ -39,13 +39,13 @@ jobs: # Upload the results to GitHub's code scanning dashboard. - name: "Upload SAST results to code-scanning" - uses: github/codeql-action/upload-sarif@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v4.36.0 + uses: github/codeql-action/upload-sarif@87557b9c84dde89fdd9b10e88954ac2f4248e463 # v4.36.1 with: sarif_file: fluidscan-sast-results.sarif category: fluidattacks-sast - name: "Upload SCA results to code-scanning" - uses: github/codeql-action/upload-sarif@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v4.36.0 + uses: github/codeql-action/upload-sarif@87557b9c84dde89fdd9b10e88954ac2f4248e463 # v4.36.1 with: sarif_file: fluidscan-sca-results.sarif category: fluidattacks-sca diff --git a/.github/workflows/security-scorecard.yml b/.github/workflows/security-scorecard.yml index 40e0077af9..aaf091b139 100644 --- a/.github/workflows/security-scorecard.yml +++ b/.github/workflows/security-scorecard.yml @@ -44,6 +44,6 @@ jobs: # Upload the results to GitHub's code scanning dashboard. - name: "Upload to code-scanning" - uses: github/codeql-action/upload-sarif@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v4.36.0 + uses: github/codeql-action/upload-sarif@87557b9c84dde89fdd9b10e88954ac2f4248e463 # v4.36.1 with: sarif_file: results.sarif