File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -11,12 +11,12 @@ jobs:
1111
1212 steps :
1313 - name : Checkout
14- uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
14+ uses : actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
1515 with :
1616 ref : ${{ github.event.workflow_run.head_branch }}
1717
1818 - name : Set up JDK
19- uses : actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 # v4.7.1
19+ uses : actions/setup-java@dded0888837ed1f317902acf8a20df0ad188d165 # v5.0.0
2020 with :
2121 distribution : ' temurin'
2222 java-version : ' 17'
2828 run : NO_GPG_SIGN=true ./gradlew --stacktrace check test build javadocJar publishToMavenLocal
2929
3030 - name : Upload jars
31- uses : actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
31+ uses : actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5.0.0
3232 with :
3333 name : maven-repo
3434 path : ~/.m2/repository/com/yubico/yubikit/
Original file line number Diff line number Diff line change @@ -29,22 +29,22 @@ jobs:
2929
3030 steps :
3131 - name : Checkout repository
32- uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
32+ uses : actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
3333
3434 # Initializes the CodeQL tools for scanning.
3535 - name : Initialize CodeQL
36- uses : github/codeql-action/init@7273f08caa1dcf2c2837f362f1982de0ab4dc344 # v2.22.3
36+ uses : github/codeql-action/init@fe4161a26a8629af62121b670040955b330f9af2 # v4.31.6
3737 with :
3838 languages : ${{ matrix.language }}
3939
4040 - name : Setup Java
41- uses : actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 # v4.7.1
41+ uses : actions/setup-java@dded0888837ed1f317902acf8a20df0ad188d165 # v5.0.0
4242 with :
4343 distribution : ' temurin'
4444 java-version : ' 17'
4545
4646 - name : Autobuild
47- uses : github/codeql-action/autobuild@7273f08caa1dcf2c2837f362f1982de0ab4dc344 # v2.22.3
47+ uses : github/codeql-action/autobuild@fe4161a26a8629af62121b670040955b330f9af2 # v4.31.6
4848
4949 - name : Perform CodeQL Analysis
50- uses : github/codeql-action/analyze@7273f08caa1dcf2c2837f362f1982de0ab4dc344 # v2.22.3
50+ uses : github/codeql-action/analyze@fe4161a26a8629af62121b670040955b330f9af2 # v4.31.6
Original file line number Diff line number Diff line change @@ -36,17 +36,17 @@ jobs:
3636
3737 steps :
3838 - name : Harden the runner (Audit all outbound calls)
39- uses : step-security/harden-runner@ec9f2d5744a09debf3a187a3f4f675c53b671911 # v2.13.0
39+ uses : step-security/harden-runner@df199fb7be9f65074067a9eb93f12bb4c5547cf2 # v2.13.3
4040 with :
4141 egress-policy : audit
4242
4343 - name : " Checkout code"
44- uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5 .0.0
44+ uses : actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6 .0.1
4545 with :
4646 persist-credentials : false
4747
4848 - name : " Run analysis"
49- uses : ossf/scorecard-action@05b42c624433fc40578a4040d5cf5e36ddca8cde # v2.4.2
49+ uses : ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3
5050 with :
5151 results_file : results.sarif
5252 results_format : sarif
@@ -68,14 +68,14 @@ jobs:
6868 # Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
6969 # format to the repository Actions tab.
7070 - name : " Upload artifact"
71- uses : actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
71+ uses : actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5.0.0
7272 with :
7373 name : SARIF file
7474 path : results.sarif
7575 retention-days : 5
7676
7777 # Upload the results to GitHub's code scanning dashboard.
7878 - name : " Upload to code-scanning"
79- uses : github/codeql-action/upload-sarif@3c3833e0f8c1c83d449a7478aa59c036a9165498 # v3.29.11
79+ uses : github/codeql-action/upload-sarif@fe4161a26a8629af62121b670040955b330f9af2 # v4.31.6
8080 with :
8181 sarif_file : results.sarif
Original file line number Diff line number Diff line change @@ -28,18 +28,18 @@ jobs:
2828
2929 steps :
3030 - name : Checkout repository
31- uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
31+ uses : actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
3232
3333 - name : Setup Java
34- uses : actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 # v4.7.1
34+ uses : actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 # v5.0.0
3535 with :
3636 distribution : " temurin"
3737 java-version : " 17"
3838
3939 - name : Build with Gradle
4040 run : ./gradlew spotbugsRelease spotbugsMain
4141
42- - uses : actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
42+ - uses : actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5.0.0
4343 with :
4444 name : sarif-files
4545 path : ./build/spotbugs/*.sarif
7676 ]
7777
7878 steps :
79- - uses : actions/download-artifact@634f93cb2916e3fdff6788551b99b062d0335ce0 # v5 .0.0
79+ - uses : actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53 # v6 .0.0
8080 with :
8181 name : sarif-files
8282
9696 jq -c '.' > ${OUTPUT}
9797
9898 - name : Upload SARIF for ${{ matrix.module }}
99- uses : github/codeql-action/upload-sarif@7273f08caa1dcf2c2837f362f1982de0ab4dc344 # v2.22.3
99+ uses : github/codeql-action/upload-sarif@fe4161a26a8629af62121b670040955b330f9af2 # v4.31.6
100100 with :
101101 sarif_file : spotbugs-${{ matrix.module }}.json
102102 category : spotbugs-analysis-${{ matrix.module }}
You can’t perform that action at this time.
0 commit comments