diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml index 686f7e64..990b90a9 100644 --- a/.github/workflows/docker.yml +++ b/.github/workflows/docker.yml @@ -173,7 +173,7 @@ jobs: - name: "📂 Checkout Repository Code" if: steps.version-filter.outputs.skip != 'true' - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 with: token: ${{ secrets.WORKFLOW_SECRET || secrets.GITHUB_TOKEN }} persist-credentials: false @@ -520,7 +520,7 @@ jobs: - name: "📤 Upload Image Security Scan (SARIF)" if: steps.version-filter.outputs.skip != 'true' && steps.build.conclusion == 'success' && steps.trivy.outcome == 'success' continue-on-error: true - uses: github/codeql-action/upload-sarif@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v4.36.0 + uses: github/codeql-action/upload-sarif@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2 with: sarif_file: "trivy-image-${{ matrix.version }}.sarif" category: "trivy-image-debian-${{ matrix.version }}"