diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index bef74047..a8bd4490 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -27,7 +27,7 @@ workflows: - 'swatinem/rust-cache@v2.9.2' '.github/workflows/codeql.yml': - 'actions/checkout@v7.0.1' - - 'github/codeql-action@v4.38.0' + - 'github/codeql-action@v4.38.1' '.github/workflows/container-ci.yml': - 'actions/checkout@v7.0.1' '.github/workflows/dogfood-gate.yml': @@ -144,9 +144,9 @@ dependencies: commit: 'sha1-02cb101ec7c40f2c49e1d9714d64511d8e1b74de' owner_id: 1940490 repo_id: 260749683 - 'github/codeql-action@v4.38.0': - ref: 'v4.38.0' - commit: 'sha1-b96794f015dfd88f77b49b1c93e0fa7110f94c63' + 'github/codeql-action@v4.38.1': + ref: 'v4.38.1' + commit: 'sha1-1c5b675653bb5c22dbe9b12b556ec555138e09fd' owner_id: 9919 repo_id: 259445878 'google/clusterfuzzlite@v1': diff --git a/.github/workflows/security-scan.yml b/.github/workflows/security-scan.yml index 01a43325..57da9683 100644 --- a/.github/workflows/security-scan.yml +++ b/.github/workflows/security-scan.yml @@ -24,6 +24,6 @@ permissions: jobs: scan: - uses: hyperpolymath/panic-attack/.github/workflows/scan-and-report.yml@27b3d93b11fbfc03cee695e791904d741ce2b24b # main 2026-07-07 (skip dispatch without VERISIMDB_PAT) + uses: hyperpolymath/panic-attack/.github/workflows/scan-and-report.yml@5ee25658c9f3ef54beaa911e77fbb0c823b358fc # main 2026-10-01 panic-attack#209: SHA-pinned steps (skip dispatch without VERISIMDB_PAT) secrets: VERISIMDB_PAT: ${{ secrets.VERISIMDB_PAT }}