Commit 202c60a
authored
fix: pin codeql-action/upload-sarif to SHA in scorecard workflow (#267)
## Summary
- Pin `github/codeql-action/upload-sarif` from tag reference `@v4` to
full commit SHA `@38697555549f1db7851b81482ff19f1fa5c4fedc` (v4.34.1)
- This was the only non-SHA-pinned action reference across all workflow
files
- Fixes OpenSSF Scorecard workflow failure due to org policy requiring
SHA-pinned actions
## Test plan
- [ ] Scorecard workflow runs successfully with the pinned SHA1 file changed
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
30 | 30 | | |
31 | 31 | | |
32 | 32 | | |
33 | | - | |
| 33 | + | |
34 | 34 | | |
35 | 35 | | |
0 commit comments