From 853e4cdfbb124b6ad1bb47df21cb53fe059b34d4 Mon Sep 17 00:00:00 2001
From: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Date: Fri, 02 Oct 2026 19:16:30 +0000
Subject: [PATCH] Bump the github-actions group with 3 updates
---
.github/workflows/docker-scan.yml | 2 +-
.github/workflows/codeql.yml | 4 ++--
.github/workflows/build.yml | 4 ++--
3 files changed, 5 insertions(+), 5 deletions(-)
diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml
index 327a02a..6178a77 100644
--- a/.github/workflows/build.yml
+++ b/.github/workflows/build.yml
@@ -858,7 +858,7 @@
scanners: vuln
cache: false
- name: Upload Trivy report to GitHub Security
- uses: github/codeql-action/upload-sarif@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
+ uses: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
# upload even if a preceding step failed, but not without a report to upload
if: ${{ always() && hashFiles('trivy-results.sarif') != '' }}
with:
@@ -1304,7 +1304,7 @@
scanners: vuln
cache: false
- name: Upload Trivy report to GitHub Security
- uses: github/codeql-action/upload-sarif@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
+ uses: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
# upload even if a preceding step failed, but not without a report to upload
if: ${{ always() && hashFiles('trivy-results.sarif') != '' }}
with:
diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml
index 210a692..81125ef 100644
--- a/.github/workflows/codeql.yml
+++ b/.github/workflows/codeql.yml
@@ -85,7 +85,7 @@
submodules: recursive
- name: Initialize CodeQL
- uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
+ uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}
@@ -139,6 +139,6 @@
# ---------------------------------------------------------------------
- name: Perform CodeQL Analysis
- uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
+ uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
category: "/language:${{ matrix.language }}"
diff --git a/.github/workflows/docker-scan.yml b/.github/workflows/docker-scan.yml
index f422489..02a0d43 100644
--- a/.github/workflows/docker-scan.yml
+++ b/.github/workflows/docker-scan.yml
@@ -51,7 +51,7 @@
scanners: vuln
cache: false
- name: Upload report to GitHub Security
- uses: github/codeql-action/upload-sarif@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
+ uses: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
# upload even if a preceding step failed, but not without a report to upload
if: ${{ always() && hashFiles(format('trivy-{0}.sarif', matrix.tag)) != '' }}
with:
--
Gitblit v1.10.0