File tree 7 files changed +10
-10
lines changed
7 files changed +10
-10
lines changed Original file line number Diff line number Diff line change 59
59
60
60
# Initializes the CodeQL tools for scanning.
61
61
- name : Initialize CodeQL
62
- uses : github/codeql-action/init@1813ca74c3faaa3a2da2070b9b8a0b3e7373a0d8 # v2.21.0
62
+ uses : github/codeql-action/init@0ba4244466797eb048eb91a6cd43d5c03ca8bd05 # v2.21.2
63
63
with :
64
64
languages : ${{ matrix.language }}
65
65
# If you wish to specify custom queries, you can do so here or in a config file.
72
72
# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
73
73
# If this step fails, then you should remove it and run the build manually (see below)
74
74
- name : Autobuild
75
- uses : github/codeql-action/autobuild@1813ca74c3faaa3a2da2070b9b8a0b3e7373a0d8 # v2.21.0
75
+ uses : github/codeql-action/autobuild@0ba4244466797eb048eb91a6cd43d5c03ca8bd05 # v2.21.2
76
76
77
77
# Command-line programs to run using the OS shell.
78
78
# 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun
85
85
# ./location_of_script_within_repo/buildscript.sh
86
86
87
87
- name : Perform CodeQL Analysis
88
- uses : github/codeql-action/analyze@1813ca74c3faaa3a2da2070b9b8a0b3e7373a0d8 # v2.21.0
88
+ uses : github/codeql-action/analyze@0ba4244466797eb048eb91a6cd43d5c03ca8bd05 # v2.21.2
89
89
90
90
# NOTE: Checks that the matrix job above completes successfully.
91
91
# This is necessary because the matrix strategy generates new jobs with
Original file line number Diff line number Diff line change 51
51
- name : Checkout the project repository
52
52
uses : slsa-framework/slsa-github-generator/.github/actions/secure-project-checkout@main
53
53
- name : Set up Java for publishing to Maven Central Repository
54
- uses : actions/setup-java@5ffc13f4174014e2d4d4572b3d74c3fa61aeb2c2 # v3
54
+ uses : actions/setup-java@cd89f46ac9d01407894225f350157564c9c7cee2 # v3.12.0
55
55
env :
56
56
MAVEN_USERNAME : ${{ secrets.maven-username }}
57
57
MAVEN_PASSWORD : ${{ secrets.maven-password }}
Original file line number Diff line number Diff line change 71
71
72
72
# Upload the results to GitHub's code scanning dashboard.
73
73
- name : " Upload to code-scanning"
74
- uses : github/codeql-action/upload-sarif@1813ca74c3faaa3a2da2070b9b8a0b3e7373a0d8 # v2.21.0
74
+ uses : github/codeql-action/upload-sarif@0ba4244466797eb048eb91a6cd43d5c03ca8bd05 # v2.21.2
75
75
with :
76
76
sarif_file : results.sarif
Original file line number Diff line number Diff line change 48
48
steps :
49
49
- uses : actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
50
50
- name : Set up JDK
51
- uses : actions/setup-java@5ffc13f4174014e2d4d4572b3d74c3fa61aeb2c2 # v3.11 .0
51
+ uses : actions/setup-java@cd89f46ac9d01407894225f350157564c9c7cee2 # v3.12 .0
52
52
env :
53
53
MAVEN_USERNAME : ${{ inputs.maven-username }}
54
54
MAVEN_PASSWORD : ${{ inputs.maven-password }}
Original file line number Diff line number Diff line change 53
53
54
54
- name : Setup Java
55
55
id : java
56
- uses : actions/setup-java@5ffc13f4174014e2d4d4572b3d74c3fa61aeb2c2 # v3.11 .0
56
+ uses : actions/setup-java@cd89f46ac9d01407894225f350157564c9c7cee2 # v3.12 .0
57
57
with :
58
58
distribution : " ${{ fromJson(inputs.slsa-workflow-inputs).user-java-distribution }}"
59
59
java-version : " ${{ fromJson(inputs.slsa-workflow-inputs).user-java-version }}"
Original file line number Diff line number Diff line change @@ -54,12 +54,12 @@ runs:
54
54
steps :
55
55
- uses : actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
56
56
- name : Set up JDK
57
- uses : actions/setup-java@5ffc13f4174014e2d4d4572b3d74c3fa61aeb2c2 # v3.11 .0
57
+ uses : actions/setup-java@cd89f46ac9d01407894225f350157564c9c7cee2 # v3.12 .0
58
58
with :
59
59
distribution : temurin
60
60
java-version : ${{ fromJson(inputs.slsa-workflow-inputs).jdk-version }}
61
61
- name : Setup Gradle
62
- uses : gradle/gradle-build-action@915a66c096a03101667f9df2e56c9efef558b165 # v2.6.1
62
+ uses : gradle/gradle-build-action@a4cf152f482c7ca97ef56ead29bf08bcd953284c # v2.7.0
63
63
with :
64
64
arguments : build -x test
65
65
- name : Put release artifacts in one directory
Original file line number Diff line number Diff line change 54
54
steps :
55
55
- uses : actions/checkout@96f53100ba2a5449eb71d2e6604bbcd94b9449b5 # v 3.5.2
56
56
- name : Set up JDK
57
- uses : actions/setup-java@cd89f46ac9d01407894225f350157564c9c7cee2 # v 3.11 .0
57
+ uses : actions/setup-java@cd89f46ac9d01407894225f350157564c9c7cee2 # v3.12 .0
58
58
with :
59
59
distribution : temurin
60
60
java-version : ${{ fromJson(inputs.slsa-workflow-inputs).jdk-version }}
You can’t perform that action at this time.
0 commit comments