@@ -18,11 +18,11 @@ jobs:
1818 runs-on : ubuntu-latest
1919 steps :
2020 - name : Checkout repository
21- uses : actions/checkout@v6
21+ uses : actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
2222
2323 - name : Get repo languages
2424 id : lang
25- uses : actions/github-script@v8
25+ uses : actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0
2626 with :
2727 script : |
2828 // CodeQL supports the following:
@@ -146,7 +146,7 @@ jobs:
146146
147147 - name : Continue
148148 id : continue
149- uses : actions/github-script@v8
149+ uses : actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0
150150 with :
151151 script : |
152152 // if matrix['include'] is an empty list return false, otherwise true
@@ -175,13 +175,13 @@ jobs:
175175 timeout-minutes : ${{ (matrix.language == 'swift' && 120) || 60 }}
176176 steps :
177177 - name : Checkout repository
178- uses : actions/checkout@v6
178+ uses : actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
179179 with :
180180 submodules : recursive
181181
182182 # Initializes the CodeQL tools for scanning.
183183 - name : Initialize CodeQL
184- uses : github/codeql-action/init@v4
184+ uses : github/codeql-action/init@6bc82e05fd0ea64601dd4b465378bbcf57de0314 # v4.32.1
185185 with :
186186 languages : ${{ matrix.language }}
187187 # If you wish to specify custom queries, you can do so here or in a config file.
@@ -201,10 +201,10 @@ jobs:
201201 # Autobuild attempts to build any compiled languages (C/C++, C#, Go, Java, or Swift).
202202 - name : Autobuild
203203 if : matrix.build-mode == 'autobuild'
204- uses : github/codeql-action/autobuild@v4
204+ uses : github/codeql-action/autobuild@6bc82e05fd0ea64601dd4b465378bbcf57de0314 # v4.32.1
205205
206206 - name : Perform CodeQL Analysis
207- uses : github/codeql-action/analyze@v4
207+ uses : github/codeql-action/analyze@6bc82e05fd0ea64601dd4b465378bbcf57de0314 # v4.32.1
208208 with :
209209 category : " ${{ matrix.category }}"
210210 output : sarif-results
@@ -221,13 +221,13 @@ jobs:
221221 -third\-party/**
222222
223223 - name : Upload SARIF
224- uses : github/codeql-action/upload-sarif@v4
224+ uses : github/codeql-action/upload-sarif@6bc82e05fd0ea64601dd4b465378bbcf57de0314 # v4.32.1
225225 with :
226226 category : " ${{ matrix.category }}"
227227 sarif_file : sarif-results/${{ matrix.language }}.sarif
228228
229229 - name : Upload loc as a Build Artifact
230- uses : actions/upload-artifact@v6
230+ uses : actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6.0.0
231231 with :
232232 name : sarif-results-${{ matrix.language }}-${{ runner.os }}
233233 path : sarif-results
0 commit comments