]> git.ipfire.org Git - thirdparty/zstd.git/commitdiff
Merge pull request #3804 from facebook/dependabot/github_actions/ossf/scorecard-actio...
authorYann Collet <Cyan4973@users.noreply.github.com>
Mon, 4 Mar 2024 02:57:19 +0000 (18:57 -0800)
committerGitHub <noreply@github.com>
Mon, 4 Mar 2024 02:57:19 +0000 (18:57 -0800)
Bump ossf/scorecard-action from 2.2.0 to 2.3.1

1  2 
.github/workflows/scorecards.yml

index fce0784e31f071b955750522950fabd324a070ab,f8f1f2d80e1a53c916e9b98088dc02f530742b7d..18b0db45d64724bbf67225be122f8a8e0dda103d
@@@ -27,12 -27,12 +27,12 @@@ jobs
  
      steps:
        - name: "Checkout code"
 -        uses: actions/checkout@8ade135a41bc03ea155e62e844d188df1ea18608 # tag=v3
 +        uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # tag=v3
          with:
            persist-credentials: false
  
        - name: "Run analysis"
-         uses: ossf/scorecard-action@08b4669551908b1024bb425080c797723083c031 # tag=v2.2.0
+         uses: ossf/scorecard-action@0864cf19026789058feabb7e87baa5f140aac736 # tag=v2.3.1
          with:
            results_file: results.sarif
            results_format: sarif
@@@ -51,7 -51,7 +51,7 @@@
        # Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
        # format to the repository Actions tab.
        - name: "Upload artifact"
 -        uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # tag=v3.1.3
 +        uses: actions/upload-artifact@5d5d22a31266ced268874388b861e4b58bb5c2f3 # tag=v4.3.1
          with:
            name: SARIF file
            path: results.sarif
@@@ -59,6 -59,6 +59,6 @@@
  
        # Upload the results to GitHub's code scanning dashboard.
        - name: "Upload to code-scanning"
 -        uses: github/codeql-action/upload-sarif@a09933a12a80f87b87005513f0abb1494c27a716 # tag=v2.21.4
 +        uses: github/codeql-action/upload-sarif@47b3d888fe66b639e431abf22ebca059152f1eea # tag=v3.24.5
          with:
            sarif_file: results.sarif