This commit is contained in:
dependabot[bot] 2026-03-13 12:42:00 +00:00 committed by GitHub
commit 7f54e0fd42
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -15,8 +15,8 @@ jobs:
language: [go, javascript-typescript]
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: github/codeql-action/init@v3 # SECURITY(MEDIUM-007): TODO — pin to SHA
- uses: github/codeql-action/init@v4 # SECURITY(MEDIUM-007): TODO — pin to SHA
with:
languages: ${{ matrix.language }}
- uses: github/codeql-action/autobuild@v3 # SECURITY(MEDIUM-007): TODO — pin to SHA
- uses: github/codeql-action/analyze@v3 # SECURITY(MEDIUM-007): TODO — pin to SHA
- uses: github/codeql-action/autobuild@v4 # SECURITY(MEDIUM-007): TODO — pin to SHA
- uses: github/codeql-action/analyze@v4 # SECURITY(MEDIUM-007): TODO — pin to SHA