File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change 1515 GITHUB_TOKEN : ${{secrets.PERSONAL_ACCESS_TOKEN }}
1616 run : gh pr merge --auto --squash "$PR_URL"
1717 - name : Auto approve dependabot PRs
18- uses : hmarr /auto-approve-action@f0939ea97e9205ef24d872e76833fa908a770363 # v4
18+ uses : step-security /auto-approve-action@0c28339628c8e79ab2f6813291e7e6cd584b4d30 # v4.0.0
1919 with :
2020 github-token : ${{ secrets.PERSONAL_ACCESS_TOKEN }}
Original file line number Diff line number Diff line change 1111 steps :
1212 - name : Dependabot metadata
1313 id : metadata
14- uses : dependabot/ fetch-metadata@dbb049abf0d677abbd7f7eee0375145b417fdd34 # v2.2 .0
14+ uses : step-security/dependabot- fetch-metadata@bf8fb6e0be0a711c669dc236de6e7f7374ba626e # v3.1 .0
1515 with :
1616 github-token : " ${{ secrets.PERSONAL_ACCESS_TOKEN }}"
1717 - name : Enable auto-merge for Dependabot PRs
2020 GITHUB_TOKEN : ${{secrets.PERSONAL_ACCESS_TOKEN }}
2121 run : gh pr merge --auto --squash "$PR_URL"
2222 - name : Auto approve dependabot PRs
23- uses : hmarr /auto-approve-action@f0939ea97e9205ef24d872e76833fa908a770363 # v4
23+ uses : step-security /auto-approve-action@0c28339628c8e79ab2f6813291e7e6cd584b4d30 # v4.0.0
2424 with :
2525 github-token : ${{ secrets.PERSONAL_ACCESS_TOKEN }}
Original file line number Diff line number Diff line change @@ -125,7 +125,7 @@ jobs:
125125 MAVEN_GPG_PASSPHRASE : ${{ secrets.MAVEN_GPG_PASSPHRASE }}
126126
127127 - name : Release
128- uses : softprops /action-gh-release@a6c7483a42ee9d5daced968f6c217562cd680f7f # v2
128+ uses : step-security /action-gh-release@277bfa82abcfdb73e5bbb19e213fd76532ee2be5 # v3.0.0
129129 with :
130130 generate_release_notes : true
131131 tag_name : ${{ inputs.tag }}
Original file line number Diff line number Diff line change 6363 - name : Create Pull Request
6464 id : cretae_pull_request
6565 if : steps.checkmarx-ast-cli.outputs.current_tag != steps.checkmarx-ast-cli.outputs.release_tag
66- uses : peter-evans /create-pull-request@b1ddad2c994a25fbc81a28b3ec0e368bb2021c50 # v6
66+ uses : step-security /create-pull-request@50c103da2b9ca12cd5bc013fc6931051a5aa872b # v8.1.1
6767 with :
6868 token : ${{ secrets.AUTOMATION_TOKEN }}
6969 commit-message : Update checkmarx-ast-cli to ${{ steps.checkmarx-ast-cli.outputs.release_tag }}
You can’t perform that action at this time.
0 commit comments