mirror of
https://github.com/theupdateframework/python-tuf
synced 2026-05-24 10:08:28 +00:00
Merge pull request #2941 from theupdateframework/dependabot/github_actions/action-dependencies-36c9f0f7bd
build(deps): bump the action-dependencies group across 1 directory with 2 updates
This commit is contained in:
commit
be4f314d75
3 changed files with 4 additions and 4 deletions
4
.github/workflows/codeql-analysis.yml
vendored
4
.github/workflows/codeql-analysis.yml
vendored
|
|
@ -28,9 +28,9 @@ jobs:
|
|||
persist-credentials: false
|
||||
|
||||
- name: Initialize CodeQL
|
||||
uses: github/codeql-action/init@v4 # zizmor: ignore[unpinned-uses]
|
||||
uses: github/codeql-action/init@v4.35.3 # zizmor: ignore[unpinned-uses]
|
||||
with:
|
||||
languages: 'python'
|
||||
|
||||
- name: Perform CodeQL Analysis
|
||||
uses: github/codeql-action/analyze@v4 # zizmor: ignore[unpinned-uses]
|
||||
uses: github/codeql-action/analyze@v4.35.3 # zizmor: ignore[unpinned-uses]
|
||||
|
|
|
|||
2
.github/workflows/dependency-review.yml
vendored
2
.github/workflows/dependency-review.yml
vendored
|
|
@ -20,4 +20,4 @@ jobs:
|
|||
with:
|
||||
persist-credentials: false
|
||||
- name: 'Dependency Review'
|
||||
uses: actions/dependency-review-action@v4 # zizmor: ignore[unpinned-uses]
|
||||
uses: actions/dependency-review-action@v4.9.0 # zizmor: ignore[unpinned-uses]
|
||||
2
.github/workflows/scorecards.yml
vendored
2
.github/workflows/scorecards.yml
vendored
|
|
@ -37,6 +37,6 @@ jobs:
|
|||
publish_results: true
|
||||
|
||||
- name: "Upload to code-scanning dashboard"
|
||||
uses: github/codeql-action/upload-sarif@v4 # zizmor: ignore[unpinned-uses]
|
||||
uses: github/codeql-action/upload-sarif@v4.35.3 # zizmor: ignore[unpinned-uses]
|
||||
with:
|
||||
sarif_file: results.sarif
|
||||
|
|
|
|||
Loading…
Reference in a new issue