diff --git a/.github/workflows/analysis-and-scans.yml b/.github/workflows/analysis-and-scans.yml index 98b681c5..f3a62de7 100644 --- a/.github/workflows/analysis-and-scans.yml +++ b/.github/workflows/analysis-and-scans.yml @@ -19,13 +19,13 @@ jobs: uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3 - name: Initialize - uses: github/codeql-action/init@46ed16ded91731b2df79a2893d3aea8e9f03b5c4 # v2 + uses: github/codeql-action/init@489225d82a57396c6f426a40e66d461b16b3461d # v2 - name: Autobuild - uses: github/codeql-action/autobuild@46ed16ded91731b2df79a2893d3aea8e9f03b5c4 # v2 + uses: github/codeql-action/autobuild@489225d82a57396c6f426a40e66d461b16b3461d # v2 - name: Perform analysis and upload results - uses: github/codeql-action/analyze@46ed16ded91731b2df79a2893d3aea8e9f03b5c4 # v2 + uses: github/codeql-action/analyze@489225d82a57396c6f426a40e66d461b16b3461d # v2 njsscan: name: NJS Scan @@ -41,7 +41,7 @@ jobs: args: '. --sarif --output results.sarif || true' - name: Upload results - uses: github/codeql-action/upload-sarif@46ed16ded91731b2df79a2893d3aea8e9f03b5c4 # v2 + uses: github/codeql-action/upload-sarif@489225d82a57396c6f426a40e66d461b16b3461d # v2 with: sarif_file: results.sarif @@ -58,6 +58,6 @@ jobs: id: analysis - name: Upload results - uses: github/codeql-action/upload-sarif@46ed16ded91731b2df79a2893d3aea8e9f03b5c4 # v2 + uses: github/codeql-action/upload-sarif@489225d82a57396c6f426a40e66d461b16b3461d # v2 with: sarif_file: ${{ steps.analysis.outputs.sarifFile }}