File tree Expand file tree Collapse file tree 4 files changed +5
-5
lines changed Expand file tree Collapse file tree 4 files changed +5
-5
lines changed Original file line number Diff line number Diff line change @@ -29,11 +29,11 @@ jobs:
2929 sudo apt-get update
3030 sudo apt-get install -y libze1 libze-dev
3131 - name : Initialize CodeQL
32- uses : github/codeql-action/init@64d10c13136e1c5bce3e5fbde8d4906eeaafc885 # v3
32+ uses : github/codeql-action/init@16140ae1a102900babc80a33c44059580f687047 # v3
3333 with :
3434 languages : ' go'
3535
3636 - name : Perform CodeQL Analysis
37- uses : github/codeql-action/analyze@64d10c13136e1c5bce3e5fbde8d4906eeaafc885 # v3
37+ uses : github/codeql-action/analyze@16140ae1a102900babc80a33c44059580f687047 # v3
3838 with :
3939 category : " /language:go"
Original file line number Diff line number Diff line change @@ -113,7 +113,7 @@ jobs:
113113 echo "image_sha=$(docker inspect --format='{{index .RepoDigests 0}}' ${{ inputs.registry }}/${{ matrix.image }}:${{ inputs.image_tag }})" >> $GITHUB_OUTPUT
114114 - name : Install cosign
115115 if : ${{ inputs.image_tag != 'devel' }}
116- uses : sigstore/cosign-installer@d7543c93d881b35a8faa02e8e3605f69b7a1ce62 # v3.10 .0
116+ uses : sigstore/cosign-installer@faadad0cce49287aee09b3a48701e75088a2c6ad # v4.0 .0
117117 - name : Keyless image sign
118118 if : ${{ inputs.image_tag != 'devel' }}
119119 run : |
Original file line number Diff line number Diff line change 2626 results_format : sarif
2727 publish_results : true
2828 - name : " Upload results to security"
29- uses : github/codeql-action/upload-sarif@64d10c13136e1c5bce3e5fbde8d4906eeaafc885 # v3
29+ uses : github/codeql-action/upload-sarif@16140ae1a102900babc80a33c44059580f687047 # v3
3030 with :
3131 sarif_file : results.sarif
Original file line number Diff line number Diff line change 3131 format : sarif
3232 output : trivy-report.sarif
3333 - name : Upload sarif report to GitHub Security tab
34- uses : github/codeql-action/upload-sarif@64d10c13136e1c5bce3e5fbde8d4906eeaafc885 # v3
34+ uses : github/codeql-action/upload-sarif@16140ae1a102900babc80a33c44059580f687047 # v3
3535 with :
3636 sarif_file : trivy-report.sarif
You can’t perform that action at this time.
0 commit comments