Skip to content

Commit 4168ff2

Browse files
committed
fix: resolve codeql-action tag object SHA to actual commit SHA
- codeql-action/upload-sarif, init, autobuild, analyze: f35333b → ff0a06e - Fixes Scorecard 'imposter commit' verification error
1 parent ae02af1 commit 4168ff2

2 files changed

Lines changed: 4 additions & 4 deletions

File tree

.github/workflows/codeql.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -35,16 +35,16 @@ jobs:
3535
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
3636

3737
- name: Initialize CodeQL
38-
uses: github/codeql-action/init@f35333b910470a5408cb081b68f0701254a7d27b # v3.28.18
38+
uses: github/codeql-action/init@ff0a06e83cb2de871e5a09832bc6a81e7276941f # v3.28.18
3939
with:
4040
languages: ${{ matrix.language }}
4141
# Use extended queries for more thorough analysis
4242
queries: security-extended
4343

4444
- name: Autobuild
45-
uses: github/codeql-action/autobuild@f35333b910470a5408cb081b68f0701254a7d27b # v3.28.18
45+
uses: github/codeql-action/autobuild@ff0a06e83cb2de871e5a09832bc6a81e7276941f # v3.28.18
4646

4747
- name: Perform CodeQL Analysis
48-
uses: github/codeql-action/analyze@f35333b910470a5408cb081b68f0701254a7d27b # v3.28.18
48+
uses: github/codeql-action/analyze@ff0a06e83cb2de871e5a09832bc6a81e7276941f # v3.28.18
4949
with:
5050
category: "/language:${{ matrix.language }}"

.github/workflows/scorecard.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -45,6 +45,6 @@ jobs:
4545
publish_results: true
4646

4747
- name: "Upload SARIF to GitHub Security tab"
48-
uses: github/codeql-action/upload-sarif@f35333b910470a5408cb081b68f0701254a7d27b # v3.28.18
48+
uses: github/codeql-action/upload-sarif@ff0a06e83cb2de871e5a09832bc6a81e7276941f # v3.28.18
4949
with:
5050
sarif_file: results.sarif

0 commit comments

Comments
 (0)