Skip to content

Commit 833fe22

Browse files
committed
pin the versions instead of digests
1 parent 3b32f53 commit 833fe22

File tree

2 files changed

+5
-5
lines changed

2 files changed

+5
-5
lines changed

.github/workflows/publish-to-ghpages.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ jobs:
1111

1212
steps:
1313
- name: Checkout Repository
14-
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
14+
uses: actions/checkout@v5
1515

1616
- name: Install Dependencies
1717
run: |

.github/workflows/scorecard.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -35,19 +35,19 @@ jobs:
3535
id-token: write
3636
steps:
3737
- name: "Checkout code"
38-
uses: actions/checkout@8edcb1bdb4e267140fa742c62e395cd74f332709
38+
uses: actions/checkout@v5
3939
with:
4040
persist-credentials: false
4141

4242
- name: "Run analysis"
43-
uses: ossf/scorecard-action@f35c64557cf912815708bb1126d9948f3e459487
43+
uses: ossf/scorecard-action@v2.4.2
4444
with:
4545
results_file: results.sarif
4646
results_format: sarif
4747
publish_results: true
4848

4949
- name: "Upload artifact"
50-
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
50+
uses: actions/upload-artifact@v4.6.2
5151
with:
5252
name: SARIF file
5353
path: results.sarif
@@ -56,7 +56,7 @@ jobs:
5656
# Upload the results to GitHub's code scanning dashboard (optional).
5757
# Commenting out will disable upload of results to your repo's Code Scanning dashboard
5858
- name: "Upload to code-scanning"
59-
uses: github/codeql-action/upload-sarif@3c3833e0f8c1c83d449a7478aa59c036a9165498 # v3.29.11
59+
uses: github/codeql-action/upload-sarif@v3.29.11
6060
with:
6161
sarif_file: results.sarif
6262

0 commit comments

Comments
 (0)