diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 8f03e77..9e57958 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -152,7 +152,7 @@ jobs: fetch-depth: 0 # trufflehog walks git history - name: Set up uv - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 + uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 - name: Install trufflehog (verified release binary; the hook runs with --no-update) # Download the pinned release tarball and verify its SHA-256 against the @@ -221,7 +221,7 @@ jobs: persist-credentials: false - name: Initialize CodeQL - uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 + uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 with: languages: ${{ matrix.language }} # Neither Python nor workflows compile: there is no build to observe, @@ -231,4 +231,4 @@ jobs: queries: security-extended - name: Analyze - uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 + uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 diff --git a/.github/workflows/plumber.yml b/.github/workflows/plumber.yml index e016f37..7cf4324 100644 --- a/.github/workflows/plumber.yml +++ b/.github/workflows/plumber.yml @@ -52,7 +52,7 @@ jobs: persist-credentials: false - name: Plumber compliance scan - uses: getplumber/plumber@10837e44cddfed934eaa2b509e677286af23e149 # v0.4.63 + uses: getplumber/plumber@de6c889e24c9147baa064db656b71c8e98595d15 # v0.5.8 with: version: "v0.4.3" verify-attestation: "true" # check the binary's SLSA provenance before running diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 37685da..918ed50 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -80,6 +80,6 @@ jobs: publish_results: true # publish to the OpenSSF viewer (drives the README badge) - name: Upload SARIF to Code Scanning - uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 + uses: github/codeql-action/upload-sarif@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 with: sarif_file: results.sarif