Skip to content

Commit 40ab611

Browse files
committed
build: update scan workflow
- Update actions to their latest versions. - Use SHA to (potentially) allow enabling Dependabot. - Add Go Modules caching using `actions/setup-go` (supported since >=v3). Signed-off-by: Hidde Beydals <[email protected]>
1 parent 4286a7a commit 40ab611

File tree

1 file changed

+13
-9
lines changed

1 file changed

+13
-9
lines changed

.github/workflows/scan.yaml

+13-9
Original file line numberDiff line numberDiff line change
@@ -17,9 +17,10 @@ jobs:
1717
name: FOSSA
1818
runs-on: ubuntu-latest
1919
steps:
20-
- uses: actions/checkout@v3
20+
- name: Checkout
21+
uses: actions/checkout@24cb9080177205b6e8c946b17badbe402adc938f # v3.4.0
2122
- name: Run FOSSA scan and upload build data
22-
uses: fossa-contrib/fossa-action@v1
23+
uses: fossa-contrib/fossa-action@6728dc6fe9a068c648d080c33829ffbe56565023 # v2.0.0
2324
with:
2425
# FOSSA Push-Only API Token
2526
fossa-api-key: 5ee8bf422db1471e0bcf2bcb289185de
@@ -29,17 +30,20 @@ jobs:
2930
name: CodeQL
3031
runs-on: ubuntu-latest
3132
steps:
32-
- name: Checkout repository
33-
uses: actions/checkout@v3
34-
- name: Set up Go
35-
uses: actions/setup-go@v2
33+
- name: Checkout
34+
uses: actions/checkout@24cb9080177205b6e8c946b17badbe402adc938f # v3.4.0
35+
- name: Setup Go
36+
uses: actions/setup-go@4d34df0c2316fe8122ab82dc22947d607c0c91f9 # v4.0.0
3637
with:
3738
go-version: 1.20.x
39+
cache-dependency-path: |
40+
**/go.sum
41+
**/go.mod
3842
- name: Initialize CodeQL
39-
uses: github/codeql-action/init@v2
43+
uses: github/codeql-action/init@168b99b3c22180941ae7dbdd5f5c9678ede476ba # v2.2.7
4044
with:
4145
languages: go
4246
- name: Autobuild
43-
uses: github/codeql-action/autobuild@v2
47+
uses: github/codeql-action/autobuild@168b99b3c22180941ae7dbdd5f5c9678ede476ba # v2.2.7
4448
- name: Perform CodeQL Analysis
45-
uses: github/codeql-action/analyze@v2
49+
uses: github/codeql-action/analyze@168b99b3c22180941ae7dbdd5f5c9678ede476ba # v2.2.7

0 commit comments

Comments
 (0)