diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 65adec61..dfaeb7fb 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -31,11 +31,11 @@ jobs: uses: actions/checkout@v6 - name: Initialize CodeQL - uses: github/codeql-action/init@v4 + uses: github/codeql-action/init@v4.35.2 with: languages: ${{ matrix.language }} - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@v4 + uses: github/codeql-action/analyze@v4.35.2 with: category: "/language:${{ matrix.language }}" diff --git a/.github/workflows/osv-scanner.yml b/.github/workflows/osv-scanner.yml index 253bcea0..765aa4de 100644 --- a/.github/workflows/osv-scanner.yml +++ b/.github/workflows/osv-scanner.yml @@ -19,7 +19,7 @@ permissions: jobs: osv-scan: name: OSV Vulnerability Scan - uses: google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml@v2.3.3 + uses: google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml@v2.3.5 with: fail-on-vuln: false scan-args: |-