diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index a6b1687..ae68d77 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -28,7 +28,7 @@ jobs: - name: Upload coverage if: matrix.os == 'ubuntu-latest' && matrix.go-version == '1.26' - uses: codecov/codecov-action@57e3a136b779b570ffcdbf80b3bdc90e7fab3de2 # v6 + uses: codecov/codecov-action@e79a6962e0d4c0c17b229090214935d2e33f8354 # v6 with: files: coverage.out continue-on-error: true @@ -63,7 +63,7 @@ jobs: go-version: '1.26' - name: golangci-lint - uses: golangci/golangci-lint-action@1e7e51e771db61008b38414a730f564565cf7c20 # v9 + uses: golangci/golangci-lint-action@82606bf257cbaff209d206a39f5134f0cfbfd2ee # v9 with: version: v2.11.4 args: --timeout=5m diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index d762f0a..26654e7 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -59,6 +59,6 @@ jobs: # SARIF into the Security tab so findings show up per-PR. - name: Upload to code-scanning - uses: github/codeql-action/upload-sarif@9e0d7b8d25671d64c341c19c0152d693099fb5ba # v4 + uses: github/codeql-action/upload-sarif@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v4 with: sarif_file: results.sarif diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 808e6b9..22bfd1e 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -43,6 +43,6 @@ jobs: format: sarif output: trivy-fs.sarif - if: always() - uses: github/codeql-action/upload-sarif@9e0d7b8d25671d64c341c19c0152d693099fb5ba # v4 + uses: github/codeql-action/upload-sarif@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v4 with: sarif_file: trivy-fs.sarif