Skip to content

Commit 10fa94a

Browse files
Merge pull request #56108 from nextcloud/ci/noid/action-pin-versions
ci(actions): Pin action versions by hash
2 parents f77c4f7 + 9198244 commit 10fa94a

File tree

1 file changed

+5
-3
lines changed

1 file changed

+5
-3
lines changed

.github/workflows/codeql.yml

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -32,16 +32,18 @@ jobs:
3232
build-mode: none
3333
steps:
3434
- name: Checkout repository
35-
uses: actions/checkout@v5
35+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
36+
with:
37+
persist-credentials: false
3638

3739
- name: Initialize CodeQL
38-
uses: github/codeql-action/init@v3
40+
uses: github/codeql-action/init@5d5cd550d3e189c569da8f16ea8de2d821c9bf7a # v3.31.2
3941
with:
4042
languages: ${{ matrix.language }}
4143
build-mode: ${{ matrix.build-mode }}
4244
config-file: ./.github/codeql-config.yml
4345

4446
- name: Perform CodeQL Analysis
45-
uses: github/codeql-action/analyze@v3
47+
uses: github/codeql-action/analyze@5d5cd550d3e189c569da8f16ea8de2d821c9bf7a # v3.31.2
4648
with:
4749
category: "/language:${{matrix.language}}"

0 commit comments

Comments
 (0)