diff --git a/.github/workflows/pipeline.yml b/.github/workflows/pipeline.yml index 8b0d5d0c..7b2856a9 100644 --- a/.github/workflows/pipeline.yml +++ b/.github/workflows/pipeline.yml @@ -146,7 +146,7 @@ jobs: exit-code: "1" # Fail the build! - name: Upload Trivy scan results to GitHub Security tab - uses: github/codeql-action/upload-sarif@4355270be187e1b672a7a1c7c7bae5afdc1ab94a # v3.24.10 + uses: github/codeql-action/upload-sarif@8f596b4ae3cb3c588a5c46780b86dd53fef16c52 # v3.25.2 if: always() # Bypass non-zero exit code.. with: sarif_file: "trivy-results.sarif" diff --git a/.github/workflows/scan.yml b/.github/workflows/scan.yml index 3dbea9e2..3daef849 100644 --- a/.github/workflows/scan.yml +++ b/.github/workflows/scan.yml @@ -31,7 +31,7 @@ jobs: severity: "CRITICAL,HIGH" exit-code: "1" # Fail the build! - name: Upload Trivy scan results to GitHub Security tab - uses: github/codeql-action/upload-sarif@4355270be187e1b672a7a1c7c7bae5afdc1ab94a # v3.24.10 + uses: github/codeql-action/upload-sarif@8f596b4ae3cb3c588a5c46780b86dd53fef16c52 # v3.25.2 if: always() # Bypass non-zero exit code.. with: sarif_file: "trivy-results.sarif"