File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -23,15 +23,15 @@ jobs:
2323
2424 steps :
2525 - name : Checkout repository
26- uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
26+ uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v5
2727
2828 - name : Set up Node.js
29- uses : actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5
29+ uses : actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
3030 with :
3131 node-version : ' 20' # Use latest LTS
3232
3333 - name : Cache node modules
34- uses : actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809 # v4
34+ uses : actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v4
3535 with :
3636 path : |
3737 node_modules
@@ -41,15 +41,15 @@ jobs:
4141 run : npm ci
4242
4343 - name : Initialize CodeQL
44- uses : github/codeql-action/init@192325c86100d080feab897ff886c34abd4c83a3 # v3
44+ uses : github/codeql-action/init@9e0d7b8d25671d64c341c19c0152d693099fb5ba # v3
4545 with :
4646 languages : ${{ matrix.language }}
4747 queries : security-and-quality
4848
4949 - name : Autobuild
50- uses : github/codeql-action/autobuild@192325c86100d080feab897ff886c34abd4c83a3 # v3
50+ uses : github/codeql-action/autobuild@9e0d7b8d25671d64c341c19c0152d693099fb5ba # v3
5151
5252 - name : Perform CodeQL Analysis
53- uses : github/codeql-action/analyze@192325c86100d080feab897ff886c34abd4c83a3 # v3
53+ uses : github/codeql-action/analyze@9e0d7b8d25671d64c341c19c0152d693099fb5ba # v3
5454 with :
5555 category : " /language:${{ matrix.language }}"
Original file line number Diff line number Diff line change @@ -18,10 +18,10 @@ jobs:
1818
1919 steps :
2020 - name : Checkout code
21- uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
21+ uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v5
2222
2323 - name : Set up Node.js
24- uses : actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5
24+ uses : actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
2525 with :
2626 node-version : " 20"
2727 cache : " npm"
Original file line number Diff line number Diff line change 88 build :
99 runs-on : ubuntu-latest
1010 steps :
11- - uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
11+ - uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v5
1212 - name : Install modules
1313 run : npm ci
1414 - name : Run ESLint
1818 name : Check dependency manifest/lockfile pairs
1919 runs-on : ubuntu-latest
2020 steps :
21- - uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
21+ - uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v5
2222 - name : Verify each Dependabot-managed npm directory has package.json and package-lock.json
2323 shell : bash
2424 run : |
Original file line number Diff line number Diff line change 1616 attestations : write # Required for actions/attest-build-provenance
1717
1818 steps :
19- - uses : actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6
20- - uses : actions/setup-node@395ad3262231945c25e8478fd5baf05154b1d79f # v6
19+ - uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
20+ - uses : actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6
2121 with :
2222 node-version : ' 20'
2323 registry-url : ' https://registry.npmjs.org'
4444 run : cp "$BUNDLE_PATH" "two.js-${TAG}.intoto.jsonl"
4545
4646 - name : Upload provenance bundle as artifact
47- uses : actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
47+ uses : actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
4848 with :
4949 name : provenance-bundle-${{ github.ref_name }}
5050 path : two.js-${{ github.ref_name }}.intoto.jsonl
Original file line number Diff line number Diff line change 2020
2121 steps :
2222 - name : Checkout code
23- uses : actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
23+ uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
2424 with :
2525 persist-credentials : false
2626
3232 publish_results : true
3333
3434 - name : Upload results to GitHub Security tab
35- uses : github/codeql-action/upload-sarif@5c8a8a642e79153f5d047b10ec1cba1d1cc65699 # v3 .35.1
35+ uses : github/codeql-action/upload-sarif@9e0d7b8d25671d64c341c19c0152d693099fb5ba # v4 .35.5
3636 with :
3737 sarif_file : results.sarif
3838 wait-for-processing : true
You can’t perform that action at this time.
0 commit comments