File tree Expand file tree Collapse file tree 5 files changed +6
-6
lines changed Expand file tree Collapse file tree 5 files changed +6
-6
lines changed Original file line number Diff line number Diff line change 1717 - name : Checkout
1818 uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
1919 - name : Ensure SHA pinned actions
20- uses : zgosalvez/github-actions-ensure-sha-pinned-actions@fc87bb5b5a97953d987372e74478de634726b3e5 # v3 .0.25
20+ uses : zgosalvez/github-actions-ensure-sha-pinned-actions@9e9574ef04ea69da568d6249bd69539ccc704e74 # v4 .0.0
2121 with :
2222 # slsa-github-generator requires using a semver tag for reusable workflows.
2323 # See: https://github.com/slsa-framework/slsa-github-generator#referencing-slsa-builders-and-generators
Original file line number Diff line number Diff line change 3636 output : ' trivy-results.sarif'
3737 severity : ' CRITICAL,HIGH'
3838 - name : Install Cosign
39- uses : sigstore/cosign-installer@7e8b541eb2e61bf99390e1afd4be13a184e9ebc5 # v3.10.1
39+ uses : sigstore/cosign-installer@faadad0cce49287aee09b3a48701e75088a2c6ad # v4.0.0
4040 - name : Publish Capsule
4141 id : publish-capsule
4242 uses : peak-scale/github-actions/make-ko-publish@a441cca016861c546ab7e065277e40ce41a3eb84 # v0.2.0
Original file line number Diff line number Diff line change 4545 chart-digest : ${{ steps.helm_publish.outputs.digest }}
4646 steps :
4747 - uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
48- - uses : sigstore/cosign-installer@7e8b541eb2e61bf99390e1afd4be13a184e9ebc5 # v3.10.1
48+ - uses : sigstore/cosign-installer@faadad0cce49287aee09b3a48701e75088a2c6ad # v4.0.0
4949 - name : " Extract Version"
5050 id : extract_version
5151 run : |
Original file line number Diff line number Diff line change 2828 - uses : creekorful/goreportcard-action@1f35ced8cdac2cba28c9a2f2288a16aacfd507f9 # v1.0
2929 - uses : anchore/sbom-action/download-syft@8e94d75ddd33f69f691467e42275782e4bfefe84
3030 - name : Install Cosign
31- uses : sigstore/cosign-installer@7e8b541eb2e61bf99390e1afd4be13a184e9ebc5 # v3.10.1
31+ uses : sigstore/cosign-installer@faadad0cce49287aee09b3a48701e75088a2c6ad # v4.0.0
3232 - name : Run GoReleaser
3333 uses : goreleaser/goreleaser-action@e435ccd777264be153ace6237001ef4d979d3a7a # v6.4.0
3434 with :
Original file line number Diff line number Diff line change @@ -31,12 +31,12 @@ jobs:
3131 repo_token : ${{ secrets.SCORECARD_READ_TOKEN }}
3232 publish_results : true
3333 - name : Upload artifact
34- uses : actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
34+ uses : actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5.0.0
3535 with :
3636 name : SARIF file
3737 path : results.sarif
3838 retention-days : 5
3939 - name : Upload to code-scanning
40- uses : github/codeql-action/upload-sarif@d198d2fabf39a7f36b5ce57ce70d4942944f006e # v3 .31.0
40+ uses : github/codeql-action/upload-sarif@0499de31b99561a6d14a36a5f662c2a54f91beee # v4 .31.2
4141 with :
4242 sarif_file : results.sarif
You can’t perform that action at this time.
0 commit comments