diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index dae1cf68d1..78a8ef68f7 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -25,9 +25,9 @@ jobs: uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab - name: Initialize CodeQL - uses: github/codeql-action/init@b2c19fb9a2a485599ccf4ed5d65527d94bc57226 + uses: github/codeql-action/init@f3feb00acb00f31a6f60280e6ace9ca31d91c76a with: languages: 'python' - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@b2c19fb9a2a485599ccf4ed5d65527d94bc57226 + uses: github/codeql-action/analyze@f3feb00acb00f31a6f60280e6ace9ca31d91c76a diff --git a/.github/workflows/scorecards.yml b/.github/workflows/scorecards.yml index e3377cfd0d..d8cccac918 100644 --- a/.github/workflows/scorecards.yml +++ b/.github/workflows/scorecards.yml @@ -34,6 +34,6 @@ jobs: publish_results: true - name: "Upload to code-scanning dashboard" - uses: github/codeql-action/upload-sarif@b2c19fb9a2a485599ccf4ed5d65527d94bc57226 + uses: github/codeql-action/upload-sarif@f3feb00acb00f31a6f60280e6ace9ca31d91c76a with: sarif_file: results.sarif diff --git a/requirements/pinned.txt b/requirements/pinned.txt index f24a40fab2..903f44de40 100644 --- a/requirements/pinned.txt +++ b/requirements/pinned.txt @@ -5,6 +5,6 @@ cryptography==40.0.2 # via securesystemslib idna==3.4 # via requests pycparser==2.21 # via cffi pynacl==1.5.0 # via securesystemslib -requests==2.28.2 +requests==2.29.0 securesystemslib[crypto,pynacl]==0.28.0 urllib3==1.26.15 # via requests diff --git a/requirements/test.txt b/requirements/test.txt index 4792dbd7d4..70f52e6d85 100644 --- a/requirements/test.txt +++ b/requirements/test.txt @@ -4,4 +4,4 @@ -r pinned.txt # coverage measurement -coverage==7.2.3 +coverage==7.2.5