From 6280e556dc72692e7607167ffc2d498da57b7e09 Mon Sep 17 00:00:00 2001 From: Scott Straughan Date: Fri, 7 Mar 2025 08:44:45 +0000 Subject: [PATCH 1/5] Removed version to see what is the latest. --- .github/workflows/codeql.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 4bb9107..c8da996 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -38,7 +38,7 @@ jobs: uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 - name: Initialize CodeQL - uses: github/codeql-action/init@b611370bb5703a7efb587f9d136a52ea24c5c38c + uses: github/codeql-action/init with: languages: ${{ matrix.language }} build-mode: ${{ matrix.build-mode }} @@ -54,6 +54,6 @@ jobs: exit 1 - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@b611370bb5703a7efb587f9d136a52ea24c5c38c + uses: github/codeql-action/analyze with: category: "/language:${{matrix.language}}" From 46ad6c241c32b3f982cd04cb8126d9af92e5ff8e Mon Sep 17 00:00:00 2001 From: Scott Straughan Date: Fri, 7 Mar 2025 08:46:10 +0000 Subject: [PATCH 2/5] Removed version to see what is the latest. --- .github/workflows/codeql.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index c8da996..a400dbe 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -38,7 +38,7 @@ jobs: uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 - name: Initialize CodeQL - uses: github/codeql-action/init + uses: github/codeql-action/init@2.20.6 with: languages: ${{ matrix.language }} build-mode: ${{ matrix.build-mode }} @@ -54,6 +54,6 @@ jobs: exit 1 - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze + uses: github/codeql-action/analyze@2.20.6 with: category: "/language:${{matrix.language}}" From def579f2fd2be2b873a6f2e7208c87b7fa7f1718 Mon Sep 17 00:00:00 2001 From: Scott Straughan Date: Fri, 7 Mar 2025 08:50:46 +0000 Subject: [PATCH 3/5] Add dependabot dependency checking for actions. --- .github/dependabot.yml | 4 ++++ .github/workflows/codeql.yml | 4 ++-- 2 files changed, 6 insertions(+), 2 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 6134fd6..4d9c3df 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -5,3 +5,7 @@ updates: directory: ''/' schedule: interval: 'weekly' + - package-ecosystem: 'github-actions' + directory: ''/' + schedule: + interval: 'weekly' diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index a400dbe..4bb9107 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -38,7 +38,7 @@ jobs: uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 - name: Initialize CodeQL - uses: github/codeql-action/init@2.20.6 + uses: github/codeql-action/init@b611370bb5703a7efb587f9d136a52ea24c5c38c with: languages: ${{ matrix.language }} build-mode: ${{ matrix.build-mode }} @@ -54,6 +54,6 @@ jobs: exit 1 - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@2.20.6 + uses: github/codeql-action/analyze@b611370bb5703a7efb587f9d136a52ea24c5c38c with: category: "/language:${{matrix.language}}" From e1eb41c18fb65cf812d8bf160fa774d6f99364d8 Mon Sep 17 00:00:00 2001 From: Scott Straughan Date: Fri, 7 Mar 2025 08:55:25 +0000 Subject: [PATCH 4/5] Typo fix. --- .github/dependabot.yml | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 4d9c3df..6abe200 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -1,8 +1,7 @@ version: 2 - updates: - package-ecosystem: 'pip' - directory: ''/' + directory: '' schedule: interval: 'weekly' - package-ecosystem: 'github-actions' From 1975cd42cb68d3041d9a908c8f95e363cf5cc58b Mon Sep 17 00:00:00 2001 From: Scott Straughan Date: Fri, 7 Mar 2025 08:57:04 +0000 Subject: [PATCH 5/5] Typo fix. --- .github/dependabot.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 6abe200..7eaae5d 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -5,6 +5,6 @@ updates: schedule: interval: 'weekly' - package-ecosystem: 'github-actions' - directory: ''/' + directory: '' schedule: - interval: 'weekly' + interval: 'weekly' \ No newline at end of file