File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -39,14 +39,14 @@ jobs:
3939
4040 - name : Initialize CodeQL
4141 # Pinned SHA (v3 equivalent)
42- uses : github/codeql-action/init@7434149006143a4d75b82a2f411ef15b03ccc2d7
42+ uses : github/codeql-action/init@5e7a52feb2a3dfb87f88be2af33b9e2275f48de6
4343 with :
4444 languages : ${{ matrix.language }}
4545 build-mode : ${{ matrix.build-mode }}
4646 # Added security-extended to find deeper SSRF issues
4747 queries : security-extended,security-and-quality
4848
4949 - name : Perform CodeQL Analysis
50- uses : github/codeql-action/analyze@7434149006143a4d75b82a2f411ef15b03ccc2d7
50+ uses : github/codeql-action/analyze@5e7a52feb2a3dfb87f88be2af33b9e2275f48de6
5151 with :
5252 category : " /language:${{matrix.language}}"
Original file line number Diff line number Diff line change 3434
3535 - name : Upload DevSkim scan results to GitHub Security tab
3636 if : always()
37- uses : github/codeql-action/upload-sarif@7434149006143a4d75b82a2f411ef15b03ccc2d7
37+ uses : github/codeql-action/upload-sarif@5e7a52feb2a3dfb87f88be2af33b9e2275f48de6
3838 with :
3939 sarif_file : devskim-results.sarif
Original file line number Diff line number Diff line change 3232 with :
3333 args : ' . --sarif --output results.sarif || true'
3434 - name : Upload njsscan report
35- uses : github/codeql-action/upload-sarif@7434149006143a4d75b82a2f411ef15b03ccc2d7
35+ uses : github/codeql-action/upload-sarif@5e7a52feb2a3dfb87f88be2af33b9e2275f48de6
3636 with :
3737 sarif_file : results.sarif
Original file line number Diff line number Diff line change 4141 retention-days : 5
4242
4343 - name : " Upload to code-scanning"
44- uses : github/codeql-action/upload-sarif@7434149006143a4d75b82a2f411ef15b03ccc2d7
44+ uses : github/codeql-action/upload-sarif@5e7a52feb2a3dfb87f88be2af33b9e2275f48de6
4545 with :
4646 sarif_file : results.sarif
Original file line number Diff line number Diff line change 4141 args : --sarif-file-output=snyk-results.sarif
4242
4343 - name : Upload result to GitHub Code Scanning
44- uses : github/codeql-action/upload-sarif@7434149006143a4d75b82a2f411ef15b03ccc2d7
44+ uses : github/codeql-action/upload-sarif@5e7a52feb2a3dfb87f88be2af33b9e2275f48de6
4545 if : always()
4646 with :
4747 sarif_file : snyk-results.sarif
You can’t perform that action at this time.
0 commit comments