Skip to content

Commit 2514aa0

Browse files
authored
fix: use sha for external action reference to align security guideline (#2)
1 parent f889bc1 commit 2514aa0

3 files changed

Lines changed: 4 additions & 4 deletions

File tree

.github/actions/codeql-scan/action.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -61,7 +61,7 @@ runs:
6161
using: 'composite'
6262
steps:
6363
- name: Initialize CodeQL
64-
uses: github/codeql-action/init@v4.31.5
64+
uses: github/codeql-action/init@fdbfb4d2750291e159f0156def62b853c2798ca2 # v4.31.5, use sha to align security guidelines
6565
with:
6666
languages: ${{ inputs.languages }}
6767
build-mode: ${{ inputs.build-mode }}
@@ -76,7 +76,7 @@ runs:
7676

7777
- name: Perform CodeQL Analysis
7878
id: codeql-analyze
79-
uses: github/codeql-action/analyze@v4.31.5
79+
uses: github/codeql-action/analyze@fdbfb4d2750291e159f0156def62b853c2798ca2 # v4.31.5, use sha to align security guidelines
8080
with:
8181
category: ${{ inputs.category }}
8282
upload: ${{ inputs.upload-sarif }}

.github/actions/trivy-scan/action.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -66,7 +66,7 @@ runs:
6666
steps:
6767
- name: Run Trivy Scan
6868
continue-on-error: true
69-
uses: aquasecurity/trivy-action@0.33.1
69+
uses: aquasecurity/trivy-action@b6643a29fecd7f34b3597bc6acb0a98b03d33ff8 # 0.33.1, use sha to align security guidelines
7070
with:
7171
scan-type: ${{ inputs.scan-type }}
7272
scan-ref: ${{ inputs.scan-ref }}

.github/actions/trufflehog-scan/action.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -55,7 +55,7 @@ runs:
5555
- name: Run TruffleHog Scan
5656
id: trufflehog
5757
continue-on-error: true
58-
uses: trufflesecurity/trufflehog@main
58+
uses: trufflesecurity/trufflehog@aade3bff5594fe8808578dd4db3dfeae9bf2abdc # v3.91.1, use sha to align security guidelines
5959
with:
6060
path: ${{ inputs.path }}
6161
base: ${{ inputs.base }}

0 commit comments

Comments
 (0)