Skip to content

Commit 4d81eb8

Browse files
committed
Bump github/codeql-action from 4.36.1 to 4.36.2
Apply the Dependabot group update from PR #6 directly on main: dependabot branches cannot receive the CODACY_API_TOKEN secret, so the coverage upload check can never pass there. Same handling as PR #2, #3, and #5 (SOW-0012).
1 parent 01ede18 commit 4d81eb8

4 files changed

Lines changed: 6 additions & 6 deletions

File tree

.github/workflows/codacy-analysis.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -124,7 +124,7 @@ jobs:
124124

125125
- name: Upload Codacy SARIF to code scanning
126126
if: always() && hashFiles('codacy.sarif') != '' && (github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository)
127-
uses: github/codeql-action/upload-sarif@87557b9c84dde89fdd9b10e88954ac2f4248e463 # v4.36.1
127+
uses: github/codeql-action/upload-sarif@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2
128128
with:
129129
sarif_file: codacy.sarif
130130
category: codacy-local

.github/workflows/codeql.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -149,7 +149,7 @@ jobs:
149149
git
150150
151151
- name: Initialize CodeQL
152-
uses: github/codeql-action/init@87557b9c84dde89fdd9b10e88954ac2f4248e463 # v4.36.1
152+
uses: github/codeql-action/init@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2
153153
with:
154154
languages: ${{ matrix.language }}
155155
build-mode: ${{ matrix.build_mode }}
@@ -165,6 +165,6 @@ jobs:
165165
run: ${{ matrix.build_command }}
166166

167167
- name: Analyze
168-
uses: github/codeql-action/analyze@87557b9c84dde89fdd9b10e88954ac2f4248e463 # v4.36.1
168+
uses: github/codeql-action/analyze@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2
169169
with:
170170
category: ${{ matrix.category }}

.github/workflows/static-analysis.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -202,7 +202,7 @@ jobs:
202202
203203
- name: Upload gosec SARIF
204204
if: always() && hashFiles(format('{0}/gosec.sarif', matrix.module)) != '' && (github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository)
205-
uses: github/codeql-action/upload-sarif@87557b9c84dde89fdd9b10e88954ac2f4248e463 # v4.36.1
205+
uses: github/codeql-action/upload-sarif@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2
206206
with:
207207
sarif_file: ${{ matrix.module }}/gosec.sarif
208208
category: gosec/${{ matrix.module }}

.github/workflows/supply-chain-security.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -54,7 +54,7 @@ jobs:
5454
5555
- name: Upload Semgrep SARIF
5656
if: always() && hashFiles('semgrep.sarif') != '' && (github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository)
57-
uses: github/codeql-action/upload-sarif@87557b9c84dde89fdd9b10e88954ac2f4248e463 # v4.36.1
57+
uses: github/codeql-action/upload-sarif@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2
5858
with:
5959
sarif_file: semgrep.sarif
6060
category: semgrep
@@ -95,7 +95,7 @@ jobs:
9595
9696
- name: Upload OSV SARIF
9797
if: always() && hashFiles('osv.sarif') != ''
98-
uses: github/codeql-action/upload-sarif@87557b9c84dde89fdd9b10e88954ac2f4248e463 # v4.36.1
98+
uses: github/codeql-action/upload-sarif@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2
9999
with:
100100
sarif_file: osv.sarif
101101
category: osv-scanner

0 commit comments

Comments
 (0)