Merge pull request #2941 from theupdateframework/dependabot/github_actions/action-dependencies-36c9f0f7bd

build(deps): bump the action-dependencies group across 1 directory with 2 updates
This commit is contained in:
Jussi Kukkonen 2026-05-13 15:22:54 +03:00 committed by GitHub
commit be4f314d75
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 4 additions and 4 deletions

View file

@ -28,9 +28,9 @@ jobs:
persist-credentials: false
- name: Initialize CodeQL
uses: github/codeql-action/init@v4 # zizmor: ignore[unpinned-uses]
uses: github/codeql-action/init@v4.35.3 # zizmor: ignore[unpinned-uses]
with:
languages: 'python'
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v4 # zizmor: ignore[unpinned-uses]
uses: github/codeql-action/analyze@v4.35.3 # zizmor: ignore[unpinned-uses]

View file

@ -20,4 +20,4 @@ jobs:
with:
persist-credentials: false
- name: 'Dependency Review'
uses: actions/dependency-review-action@v4 # zizmor: ignore[unpinned-uses]
uses: actions/dependency-review-action@v4.9.0 # zizmor: ignore[unpinned-uses]

View file

@ -37,6 +37,6 @@ jobs:
publish_results: true
- name: "Upload to code-scanning dashboard"
uses: github/codeql-action/upload-sarif@v4 # zizmor: ignore[unpinned-uses]
uses: github/codeql-action/upload-sarif@v4.35.3 # zizmor: ignore[unpinned-uses]
with:
sarif_file: results.sarif