diff --git a/.github/workflows/sbom.yml b/.github/workflows/sbom.yml index fdf883c7..7ca096d7 100644 --- a/.github/workflows/sbom.yml +++ b/.github/workflows/sbom.yml @@ -82,7 +82,7 @@ jobs: ghcr.io/${{ github.repository_owner }}/${{ inputs.image-name }}:${SBOM_TAG} - name: Upload SBOMs as artifacts - uses: actions/upload-artifact@1746f4ab65b179e0ea60a494b83293b640dd5bba # v4.3.2 + uses: actions/upload-artifact@65462800fd760344b1a7b4382951275a0abb4808 # v4.3.3 with: name: ${{ inputs.image-name }}-sbom-${{ matrix.arch }} path: ${{ inputs.image-name }}-sbom-* diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 7f472383..593d0c37 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -59,7 +59,7 @@ jobs: # Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF # format to the repository Actions tab. - name: "Upload artifact" - uses: actions/upload-artifact@1746f4ab65b179e0ea60a494b83293b640dd5bba # v4.3.2 + uses: actions/upload-artifact@65462800fd760344b1a7b4382951275a0abb4808 # v4.3.3 with: name: SARIF file path: results.sarif