diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 9357e01..79d57ff 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -77,7 +77,7 @@ jobs: password: ${{ secrets.DOCKER_TOKEN }} - name: Build and publish init container image - uses: docker/build-push-action@16ebe778df0e7752d2cfcbd924afdbbd89c1a755 # 6.6.1 + uses: docker/build-push-action@5cd11c3a4ced054e52742c5fd54dca954e0edd85 # 6.7.0 with: push: true context: src/${{ inputs.INITCONTAINER_LANGUAGE }}/ diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 7d4259a..6a5de5d 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -73,6 +73,6 @@ jobs: # Upload the results to GitHub's code scanning dashboard. - name: "Upload to code-scanning" - uses: github/codeql-action/upload-sarif@eb055d739abdc2e8de2e5f4ba1a8b246daa779aa # v3.26.0 + uses: github/codeql-action/upload-sarif@429e1977040da7a23b6822b13c129cd1ba93dbb2 # v3.26.2 with: sarif_file: results.sarif