Bump the github-actions group with 3 updates
Bumps the github-actions group with 3 updates: [github/codeql-action/upload-sarif](https://github.com/github/codeql-action), [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action).
Updates `github/codeql-action/upload-sarif` from 4.38.1 to 4.38.2
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/1c5b675653bb5c22dbe9b12b556ec555138e09fd...2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2)
Updates `github/codeql-action/init` from 4.38.1 to 4.38.2
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/1c5b675653bb5c22dbe9b12b556ec555138e09fd...2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2)
Updates `github/codeql-action/analyze` from 4.38.1 to 4.38.2
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/1c5b675653bb5c22dbe9b12b556ec555138e09fd...2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2)
---
updated-dependencies:
- dependency-name: github/codeql-action/upload-sarif
dependency-version: 4.38.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
- dependency-name: github/codeql-action/init
dependency-version: 4.38.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
- dependency-name: github/codeql-action/analyze
dependency-version: 4.38.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
...
Signed-off-by: dependabot[bot] <support@github.com>
| | |
| | | scanners: vuln |
| | | cache: false |
| | | - name: Upload Trivy report to GitHub Security |
| | | uses: github/codeql-action/upload-sarif@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 |
| | | uses: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 |
| | | # upload even if a preceding step failed, but not without a report to upload |
| | | if: ${{ always() && hashFiles('trivy-results.sarif') != '' }} |
| | | with: |
| | |
| | | scanners: vuln |
| | | cache: false |
| | | - name: Upload Trivy report to GitHub Security |
| | | uses: github/codeql-action/upload-sarif@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 |
| | | uses: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 |
| | | # upload even if a preceding step failed, but not without a report to upload |
| | | if: ${{ always() && hashFiles('trivy-results.sarif') != '' }} |
| | | with: |
| | |
| | | submodules: recursive |
| | | |
| | | - name: Initialize CodeQL |
| | | uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 |
| | | uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 |
| | | with: |
| | | languages: ${{ matrix.language }} |
| | | build-mode: ${{ matrix.build-mode }} |
| | |
| | | # --------------------------------------------------------------------- |
| | | |
| | | - name: Perform CodeQL Analysis |
| | | uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 |
| | | uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 |
| | | with: |
| | | category: "/language:${{ matrix.language }}" |
| | |
| | | scanners: vuln |
| | | cache: false |
| | | - name: Upload report to GitHub Security |
| | | uses: github/codeql-action/upload-sarif@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 |
| | | uses: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 |
| | | # upload even if a preceding step failed, but not without a report to upload |
| | | if: ${{ always() && hashFiles(format('trivy-{0}.sarif', matrix.tag)) != '' }} |
| | | with: |