diff --git a/.github/workflows/cron-run-scan.yaml b/.github/workflows/cron-run-scan.yaml index bce473a..a99a2a1 100644 --- a/.github/workflows/cron-run-scan.yaml +++ b/.github/workflows/cron-run-scan.yaml @@ -43,7 +43,7 @@ jobs: token: ${{ steps.get-secrets.outputs.github-pat }} - name: Log into ghcr.io - uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4.1.0 + uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4.2.0 with: registry: ghcr.io username: ${{ github.actor }} diff --git a/.github/workflows/scorecards.yml b/.github/workflows/scorecards.yml index 1d9b3ed..62edf21 100644 --- a/.github/workflows/scorecards.yml +++ b/.github/workflows/scorecards.yml @@ -62,6 +62,6 @@ jobs: # Upload the results to GitHub's code scanning dashboard. - name: "Upload to code-scanning" - uses: github/codeql-action/upload-sarif@68bde559dea0fdcac2102bfdf6230c5f70eb485e # v4.35.4 + uses: github/codeql-action/upload-sarif@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v4.36.0 with: sarif_file: results.sarif