File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change 6161 using : ' composite'
6262 steps :
6363 - name : Initialize CodeQL
64- uses : github/codeql-action/init@v4.31.5
64+ uses : github/codeql-action/init@fdbfb4d2750291e159f0156def62b853c2798ca2 # v4.31.5, use sha to align security guidelines
6565 with :
6666 languages : ${{ inputs.languages }}
6767 build-mode : ${{ inputs.build-mode }}
7676
7777 - name : Perform CodeQL Analysis
7878 id : codeql-analyze
79- uses : github/codeql-action/analyze@v4.31.5
79+ uses : github/codeql-action/analyze@fdbfb4d2750291e159f0156def62b853c2798ca2 # v4.31.5, use sha to align security guidelines
8080 with :
8181 category : ${{ inputs.category }}
8282 upload : ${{ inputs.upload-sarif }}
Original file line number Diff line number Diff line change 6666 steps :
6767 - name : Run Trivy Scan
6868 continue-on-error : true
69- uses : aquasecurity/trivy-action@0.33.1
69+ uses : aquasecurity/trivy-action@b6643a29fecd7f34b3597bc6acb0a98b03d33ff8 # 0.33.1, use sha to align security guidelines
7070 with :
7171 scan-type : ${{ inputs.scan-type }}
7272 scan-ref : ${{ inputs.scan-ref }}
Original file line number Diff line number Diff line change 5555 - name : Run TruffleHog Scan
5656 id : trufflehog
5757 continue-on-error : true
58- uses : trufflesecurity/trufflehog@main
58+ uses : trufflesecurity/trufflehog@aade3bff5594fe8808578dd4db3dfeae9bf2abdc # v3.91.1, use sha to align security guidelines
5959 with :
6060 path : ${{ inputs.path }}
6161 base : ${{ inputs.base }}
You can’t perform that action at this time.
0 commit comments