Skip to content

Commit dda8415

Browse files
committed
fix: pin codeql-action/upload-sarif to SHA in scorecard workflow
Pin github/codeql-action/upload-sarif to commit SHA (v4.34.1) to satisfy org requirement for fully SHA-pinned GitHub Actions. Signed-off-by: Sebastian Mendel <info@sebastianmendel.de>
1 parent f6511f3 commit dda8415

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

.github/workflows/scorecard.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30,6 +30,6 @@ jobs:
3030
publish_results: true
3131

3232
- name: Upload to code-scanning
33-
uses: github/codeql-action/upload-sarif@v4
33+
uses: github/codeql-action/upload-sarif@38697555549f1db7851b81482ff19f1fa5c4fedc # v4.34.1
3434
with:
3535
sarif_file: results.sarif

0 commit comments

Comments
 (0)