From b6d9d25cc2d3a719d0c116984888f05b149f4467 Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Thu, 1 Aug 2024 20:35:25 +0200 Subject: [PATCH] chore(deps): update github-actions (#246) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> --- .github/workflows/ci.yaml | 6 +++--- .github/workflows/daily-trivy-scan.yaml | 2 +- .github/workflows/scorecards.yaml | 4 ++-- 3 files changed, 6 insertions(+), 6 deletions(-) diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index 5d9f6bd..b69e0da 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -12,7 +12,7 @@ permissions: read-all jobs: build: - uses: chgl/.github/.github/workflows/standard-build.yaml@db558a1cd7736b1b9f7252275a9b245dfb3b093d # v1.7.0 + uses: chgl/.github/.github/workflows/standard-build.yaml@7a1bdb5002269260fe339631451eee02f02867f4 # v1.7.4 permissions: contents: read id-token: write @@ -30,7 +30,7 @@ jobs: github-token: ${{ secrets.GITHUB_TOKEN }} lint: - uses: chgl/.github/.github/workflows/standard-lint.yaml@db558a1cd7736b1b9f7252275a9b245dfb3b093d # v1.7.0 + uses: chgl/.github/.github/workflows/standard-lint.yaml@7a1bdb5002269260fe339631451eee02f02867f4 # v1.7.4 permissions: contents: read pull-requests: write @@ -93,7 +93,7 @@ jobs: dotnet test src/FhirServerExporter.Tests.E2E/ release: - uses: chgl/.github/.github/workflows/standard-release.yaml@db558a1cd7736b1b9f7252275a9b245dfb3b093d # v1.7.0 + uses: chgl/.github/.github/workflows/standard-release.yaml@7a1bdb5002269260fe339631451eee02f02867f4 # v1.7.4 needs: - build - test diff --git a/.github/workflows/daily-trivy-scan.yaml b/.github/workflows/daily-trivy-scan.yaml index 2495375..9b1c982 100644 --- a/.github/workflows/daily-trivy-scan.yaml +++ b/.github/workflows/daily-trivy-scan.yaml @@ -22,7 +22,7 @@ jobs: severity: "CRITICAL,HIGH" - name: Upload Trivy scan results to GitHub Security tab - uses: github/codeql-action/upload-sarif@4fa2a7953630fd2f3fb380f21be14ede0169dd4f # v3.25.12 + uses: github/codeql-action/upload-sarif@afb54ba388a7dca6ecae48f608c4ff05ff4cc77a # v3.25.15 if: always() with: sarif_file: "trivy-results.sarif" diff --git a/.github/workflows/scorecards.yaml b/.github/workflows/scorecards.yaml index ea7b2d8..2019ecc 100644 --- a/.github/workflows/scorecards.yaml +++ b/.github/workflows/scorecards.yaml @@ -37,7 +37,7 @@ jobs: persist-credentials: false - name: "Run analysis" - uses: ossf/scorecard-action@dc50aa9510b46c811795eb24b2f1ba02a914e534 # v2.3.3 + uses: ossf/scorecard-action@62b2cac7ed8198b15735ed49ab1e5cf35480ba46 # v2.4.0 with: results_file: results.sarif results_format: sarif @@ -67,6 +67,6 @@ jobs: # Upload the results to GitHub's code scanning dashboard. - name: "Upload to code-scanning" - uses: github/codeql-action/upload-sarif@4fa2a7953630fd2f3fb380f21be14ede0169dd4f # v3.25.12 + uses: github/codeql-action/upload-sarif@afb54ba388a7dca6ecae48f608c4ff05ff4cc77a # v3.25.15 with: sarif_file: results.sarif