diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index b042fec..d25fab8 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -50,7 +50,7 @@ jobs: # worse on a different day, reports a clean result for a codebase it # never read. cache: false - - uses: github/codeql-action/init@5595ccaf912efad79be6eef63a5619ff05969be3 # v4.37.6 + - uses: github/codeql-action/init@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd # v4.37.7 with: languages: ${{ matrix.language }} # Go must be built for CodeQL to read it - the extractor works from a @@ -71,4 +71,4 @@ jobs: # rejects the other's: "Go does not support the none build mode" and # "GitHub Actions does not support the autobuild build mode". build-mode: ${{ matrix.language == 'go' && 'autobuild' || 'none' }} - - uses: github/codeql-action/analyze@5595ccaf912efad79be6eef63a5619ff05969be3 # v4.37.6 + - uses: github/codeql-action/analyze@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd # v4.37.7 diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index aaa430c..6511d04 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -103,6 +103,6 @@ jobs: # checksums file lists them all, so `gh attestation verify # --repo /` works for any downloaded binary or archive. - name: Attest build provenance - uses: actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373 # v4.1.1 + uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2 with: subject-checksums: build/dist/checksums.txt