diff --git a/.github/workflows/dependency-scan.yml b/.github/workflows/dependency-scan.yml index 0cc083580e..585690f5e1 100644 --- a/.github/workflows/dependency-scan.yml +++ b/.github/workflows/dependency-scan.yml @@ -24,7 +24,7 @@ jobs: ELECTRON_SKIP_BINARY_DOWNLOAD: '1' - name: Generate SBOM - uses: launchdarkly/gh-actions/actions/dependency-scan/generate-sbom@e739737ec160daae50efc7a07e6b453a104db067 # main + uses: launchdarkly/gh-actions/actions/dependency-scan/generate-sbom@a848aec9c87c29470093b22154107b83a7696374 # main with: types: 'nodejs' ensure-non-empty: 'true' @@ -37,6 +37,6 @@ jobs: - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - name: Evaluate SBOM Policy - uses: launchdarkly/gh-actions/actions/dependency-scan/evaluate-policy@e739737ec160daae50efc7a07e6b453a104db067 # main + uses: launchdarkly/gh-actions/actions/dependency-scan/evaluate-policy@a848aec9c87c29470093b22154107b83a7696374 # main with: artifacts-pattern: bom-*