diff --git a/.github/workflows/dependency-scan.yml b/.github/workflows/dependency-scan.yml index bd390fc94a..961e5c249a 100644 --- a/.github/workflows/dependency-scan.yml +++ b/.github/workflows/dependency-scan.yml @@ -27,7 +27,7 @@ jobs: ELECTRON_SKIP_BINARY_DOWNLOAD: '1' - name: Generate SBOM - uses: launchdarkly/gh-actions/actions/dependency-scan/generate-sbom@82ebcb63bbc47a198219784ccf64926bdc41755d # main + uses: launchdarkly/gh-actions/actions/dependency-scan/generate-sbom@2e6676d8c7ed1a59114d08faa22e3dbf085a1a64 # main with: types: 'nodejs' ensure-non-empty: 'true' @@ -40,6 +40,6 @@ jobs: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - name: Evaluate SBOM Policy - uses: launchdarkly/gh-actions/actions/dependency-scan/evaluate-policy@82ebcb63bbc47a198219784ccf64926bdc41755d # main + uses: launchdarkly/gh-actions/actions/dependency-scan/evaluate-policy@2e6676d8c7ed1a59114d08faa22e3dbf085a1a64 # main with: artifacts-pattern: bom-*