9
9
if : github.event_name != 'pull_request' || !github.event.pull_request.draft
10
10
runs-on : ubuntu-24.04
11
11
steps :
12
- - uses : actions/checkout@v5
12
+ - uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
13
13
- name : Run Trivy vulnerability scanner in repo mode
14
14
uses : aquasecurity/trivy-action@b6643a29fecd7f34b3597bc6acb0a98b03d33ff8 # 0.33.1
15
15
with :
21
21
severity : " CRITICAL,HIGH"
22
22
23
23
- name : Upload Trivy scan results to GitHub Security tab
24
- uses : github/codeql-action/upload-sarif@v3
24
+ uses : github/codeql-action/upload-sarif@192325c86100d080feab897ff886c34abd4c83a3 # v3
25
25
with :
26
26
sarif_file : " trivy-results.sarif"
27
27
@@ -33,14 +33,14 @@ jobs:
33
33
contents : read
34
34
security-events : write
35
35
steps :
36
- - uses : actions/checkout@v5
37
- - uses : github/codeql-action/init@v3
36
+ - uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
37
+ - uses : github/codeql-action/init@192325c86100d080feab897ff886c34abd4c83a3 # v3
38
38
with :
39
39
languages : javascript,java
40
40
41
41
# Autobuild failed for Java, so building manually
42
42
- name : Set up JDK 17 and Caching maven dependencies
43
- uses : actions/setup-java@v5
43
+ uses : actions/setup-java@dded0888837ed1f317902acf8a20df0ad188d165 # v5
44
44
with :
45
45
distribution : " temurin"
46
46
java-version : " 17"
51
51
run : ./mvnw clean package
52
52
53
53
- name : Perform CodeQL Analysis
54
- uses : github/codeql-action/analyze@v3
54
+ uses : github/codeql-action/analyze@192325c86100d080feab897ff886c34abd4c83a3 # v3
0 commit comments