diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index cce203e3..c16e9942 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -52,12 +52,12 @@ jobs: - name: Initialize CodeQL # github/codeql-action v4.37.6 - uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd + uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 with: languages: "${{ matrix.language }}" - name: Analyze repository # github/codeql-action v4.37.6 - uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd + uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 with: category: "/language:${{ matrix.language }}" diff --git a/.github/workflows/megalinter.yml b/.github/workflows/megalinter.yml index e089621a..728ec442 100644 --- a/.github/workflows/megalinter.yml +++ b/.github/workflows/megalinter.yml @@ -117,7 +117,7 @@ jobs: (github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository) # github/codeql-action v4.37.6 - uses: github/codeql-action/upload-sarif@1c5b675653bb5c22dbe9b12b556ec555138e09fd + uses: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 with: sarif_file: .reports/megalinter/megalinter-report.sarif category: megalinter diff --git a/.github/workflows/mindgarden-pages.yml b/.github/workflows/mindgarden-pages.yml index 4cfd9ee7..b0d796f2 100644 --- a/.github/workflows/mindgarden-pages.yml +++ b/.github/workflows/mindgarden-pages.yml @@ -138,7 +138,7 @@ jobs: - name: Capture consumer routes before composition id: baseline if: matrix.mode == 'current' - uses: egohygiene/relay/actions/repository-intelligence-deployment-provenance@9a6315978766c336566b9fa7139b800fa8789ba5 + uses: egohygiene/relay/actions/repository-intelligence-deployment-provenance@da172c64cbda4ae4a28434a065fbfa616c1d74c3 with: operation: capture-baseline site-directory: .cache/mindgarden/site @@ -208,7 +208,7 @@ jobs: - name: Verify current provenance and Quartz non-clobber boundary id: composition if: matrix.mode == 'current' - uses: egohygiene/relay/actions/repository-intelligence-deployment-provenance@9a6315978766c336566b9fa7139b800fa8789ba5 + uses: egohygiene/relay/actions/repository-intelligence-deployment-provenance@da172c64cbda4ae4a28434a065fbfa616c1d74c3 with: operation: verify-composition site-directory: .cache/mindgarden/site @@ -443,7 +443,7 @@ jobs: - name: Record current deployment receipt id: receipt if: needs.build.outputs.deployment-mode == 'current' - uses: egohygiene/relay/actions/repository-intelligence-deployment-provenance@9a6315978766c336566b9fa7139b800fa8789ba5 + uses: egohygiene/relay/actions/repository-intelligence-deployment-provenance@da172c64cbda4ae4a28434a065fbfa616c1d74c3 with: operation: record-receipt site-directory: .cache/mindgarden/site diff --git a/.github/workflows/ossf-scorecard.yml b/.github/workflows/ossf-scorecard.yml index 7b61391a..8faf0919 100644 --- a/.github/workflows/ossf-scorecard.yml +++ b/.github/workflows/ossf-scorecard.yml @@ -56,7 +56,7 @@ jobs: - name: Upload SARIF to code scanning if: always() # github/codeql-action v4.37.6 - uses: github/codeql-action/upload-sarif@1c5b675653bb5c22dbe9b12b556ec555138e09fd + uses: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 with: sarif_file: results.sarif category: ossf-scorecard diff --git a/.github/workflows/osv-scan.yml b/.github/workflows/osv-scan.yml index d86b0713..2cd562b4 100644 --- a/.github/workflows/osv-scan.yml +++ b/.github/workflows/osv-scan.yml @@ -678,7 +678,7 @@ jobs: (github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository) # github/codeql-action v4.37.6; immutable release pin. - uses: github/codeql-action/upload-sarif@1c5b675653bb5c22dbe9b12b556ec555138e09fd + uses: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 with: sarif_file: ".reports/osv/latest.sarif" category: "osv-scanner" diff --git a/.github/workflows/repository-intelligence-failure.yml b/.github/workflows/repository-intelligence-failure.yml index 4a1c2f1e..ec51c84a 100644 --- a/.github/workflows/repository-intelligence-failure.yml +++ b/.github/workflows/repository-intelligence-failure.yml @@ -11,7 +11,7 @@ jobs: permissions: contents: read # egohygiene/relay repository-intelligence v1.6.0 - uses: egohygiene/relay/.github/workflows/repository-intelligence.yml@9a6315978766c336566b9fa7139b800fa8789ba5 + uses: egohygiene/relay/.github/workflows/repository-intelligence.yml@da172c64cbda4ae4a28434a065fbfa616c1d74c3 with: max-depth: "21" artifact-retention-days: 30