diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 920f7bc4..8010f8be 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -30,7 +30,7 @@ jobs: sudo apt-get install -y build-essential pkg-config libssl-dev libpcsclite-dev libudev-dev - name: Initialize CodeQL - uses: github/codeql-action/init@95e58e9a2cdfd71adc6e0353d5c52f41a045d225 # v4.35.2 + uses: github/codeql-action/init@9e0d7b8d25671d64c341c19c0152d693099fb5ba # v4.35.5 with: languages: python, javascript, rust config-file: ./.github/codeql/codeql-config.yml @@ -41,4 +41,4 @@ jobs: cd rust_crypto && cargo build && cd .. - name: Analyze - uses: github/codeql-action/analyze@95e58e9a2cdfd71adc6e0353d5c52f41a045d225 # v4.35.2 + uses: github/codeql-action/analyze@9e0d7b8d25671d64c341c19c0152d693099fb5ba # v4.35.5 diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 493b6487..ef0ba4ff 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -105,7 +105,7 @@ jobs: # notes ("You may still install Cosign v2.x with cosign-installer # v4"). When migrating to Cosign v3, drop this pin and update # the sign-blob call below. - uses: sigstore/cosign-installer@cad07c2e89fa2edd6e2d7bab4c1aa38e53f76003 # v4.1.1 + uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2 with: cosign-release: 'v2.6.1' diff --git a/.github/workflows/rust-test-coverage.yml b/.github/workflows/rust-test-coverage.yml index adaecd4f..825a9460 100644 --- a/.github/workflows/rust-test-coverage.yml +++ b/.github/workflows/rust-test-coverage.yml @@ -231,7 +231,7 @@ jobs: fi - name: Upload coverage to Codecov - uses: codecov/codecov-action@57e3a136b779b570ffcdbf80b3bdc90e7fab3de2 # v5.3.1 + uses: codecov/codecov-action@e79a6962e0d4c0c17b229090214935d2e33f8354 # v5.3.1 with: token: ${{ secrets.CODECOV_TOKEN }} files: ./crypto_core/lcov.info,./rust_crypto/lcov.info diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 2c6a152f..7339b6fd 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -48,7 +48,7 @@ jobs: publish_results: true - name: Upload SARIF to GitHub Security tab - uses: github/codeql-action/upload-sarif@95e58e9a2cdfd71adc6e0353d5c52f41a045d225 # v4.35.2 + uses: github/codeql-action/upload-sarif@9e0d7b8d25671d64c341c19c0152d693099fb5ba # v4.35.5 with: sarif_file: results.sarif