File tree 1 file changed +6
-4
lines changed
1 file changed +6
-4
lines changed Original file line number Diff line number Diff line change @@ -17,17 +17,19 @@ jobs:
17
17
permissions :
18
18
# Needed to upload the results to code-scanning dashboard.
19
19
security-events : write
20
+ # Needed to publish results
21
+ id-token : write
20
22
actions : read
21
23
contents : read
22
24
23
25
steps :
24
26
- name : ' Checkout code'
25
- uses : actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b # v2.4.0
27
+ uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
26
28
with :
27
29
persist-credentials : false
28
30
29
31
- name : ' Run analysis'
30
- uses : ossf/scorecard-action@f10ec7151e838890a3fbfa27875a33f80869977b # v1.0.2
32
+ uses : ossf/scorecard-action@62b2cac7ed8198b15735ed49ab1e5cf35480ba46 # v2.4.0
31
33
with :
32
34
results_file : results.sarif
33
35
results_format : sarif
@@ -36,14 +38,14 @@ jobs:
36
38
37
39
# Upload the results as artifacts.
38
40
- name : ' Upload artifact'
39
- uses : actions/upload-artifact@3cea5372237819ed00197afe530f5a7ea3e805c8 # v2.3.1
41
+ uses : actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # v4.4.3
40
42
with :
41
43
name : SARIF file
42
44
path : results.sarif
43
45
retention-days : 5
44
46
45
47
# Upload the results to GitHub's code scanning dashboard.
46
48
- name : ' Upload to code-scanning'
47
- uses : github/codeql-action/upload-sarif@f0705a6d6f9c8ebf64b5188fdd89bc4cd20313bc # v1.0.26
49
+ uses : github/codeql-action/upload-sarif@662472033e021d55d94146f66f6058822b0b39fd # v3.27.0
48
50
with :
49
51
sarif_file : results.sarif
You can’t perform that action at this time.
0 commit comments