Skip to content

Commit 4da6669

Browse files
fix: pin Scorecard workflow actions to SHA (Scorecard finding)
1 parent 0267051 commit 4da6669

1 file changed

Lines changed: 4 additions & 4 deletions

File tree

.github/workflows/scorecard.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -16,17 +16,17 @@ jobs:
1616
security-events: write
1717
id-token: write
1818
steps:
19-
- uses: actions/checkout@v4
19+
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
2020
with: { persist-credentials: false }
21-
- uses: ossf/scorecard-action@v2.4.1
21+
- uses: ossf/scorecard-action@ea651e62978af7915d09fe2e282747c798bf2dab # v2.4.1
2222
with:
2323
results_file: results.sarif
2424
results_format: sarif
2525
publish_results: true
26-
- uses: actions/upload-artifact@v4
26+
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
2727
with:
2828
name: SARIF file
2929
path: results.sarif
30-
- uses: github/codeql-action/upload-sarif@v3
30+
- uses: github/codeql-action/upload-sarif@3b1a19a80ab047f35cbb237b5bd9bdc1e14f166c # v3
3131
with:
3232
sarif_file: results.sarif

0 commit comments

Comments
 (0)