changeset 7143:1be1eedbf593

dependabot upgrade scorecard-action:2.06->2.1.2; upload-artifact:3.1.0 3.1.2
author John Rouillard <rouilj@ieee.org>
date Wed, 15 Feb 2023 16:04:22 -0500
parents b486a5848cea
children 02c26d7de951
files .github/workflows/ossf-scorecard.yml
diffstat 1 files changed, 2 insertions(+), 2 deletions(-) [+]
line wrap: on
line diff
--- a/.github/workflows/ossf-scorecard.yml	Wed Feb 15 12:04:14 2023 -0500
+++ b/.github/workflows/ossf-scorecard.yml	Wed Feb 15 16:04:22 2023 -0500
@@ -37,7 +37,7 @@
           persist-credentials: false
 
       - name: "Run analysis"
-        uses: ossf/scorecard-action@99c53751e09b9529366343771cc321ec74e9bd3d # v2.0.6
+        uses: ossf/scorecard-action@e38b1902ae4f44df626f11ba0734b14fb91f8f86 # v2.1.2
         with:
           results_file: results.sarif
           results_format: sarif
@@ -59,7 +59,7 @@
       # Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
       # format to the repository Actions tab.
       - name: "Upload artifact"
-        uses: actions/upload-artifact@3cea5372237819ed00197afe530f5a7ea3e805c8 # v3.1.0
+        uses: actions/upload-artifact@0b7f8abb1508181956e8e162db84b466c27e18ce # v3.1.2
         with:
           name: SARIF file
           path: results.sarif

Roundup Issue Tracker: http://roundup-tracker.org/