@@ -20,31 +20,23 @@ jobs:
2020 - uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
2121 - uses : ./.github/actions/install-deps
2222 - run : make vulncheck
23- - uses : github/codeql-action/init@df32e399139a3050671466d7d9b3cbacc1cfd034 # v2.22.8
23+ - uses : github/codeql-action/init@3c3833e0f8c1c83d449a7478aa59c036a9165498 # v3.29.11
2424 with :
2525 languages : go
26- - uses : github/codeql-action/autobuild@df32e399139a3050671466d7d9b3cbacc1cfd034 # v2.22.8
27- - uses : github/codeql-action/analyze@df32e399139a3050671466d7d9b3cbacc1cfd034 # v2.22.8
26+ - uses : github/codeql-action/autobuild@3c3833e0f8c1c83d449a7478aa59c036a9165498 # v3.29.11
27+ - uses : github/codeql-action/analyze@3c3833e0f8c1c83d449a7478aa59c036a9165498 # v3.29.11
2828 # Javascript is added here for evaluating Github Action vulnerabilities
2929 # https://github.blog/2023-08-09-four-tips-to-keep-your-github-actions-workflows-secure/#2-enable-code-scanning-for-workflows
3030 analyze-github-actions :
3131 name : Analyze Github Actions
3232 if : github.repository == 'aws/karpenter-provider-aws'
3333 runs-on : ubuntu-latest
3434 permissions :
35- actions : read # github/codeql-action/init@v2
36- security-events : write # github/codeql-action/init@v2
35+ actions : read # github/codeql-action/init@v3
36+ security-events : write # github/codeql-action/init@v3
3737 steps :
3838 - uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
39- - uses : github/codeql-action/init@df32e399139a3050671466d7d9b3cbacc1cfd034 # v2.22.8
39+ - uses : github/codeql-action/init@3c3833e0f8c1c83d449a7478aa59c036a9165498 # v3.29.11
4040 with :
41- languages : javascript
42- config : |
43- packs:
44- # Use the latest version of 'codeql-javascript' published by 'advanced-security'
45- # This will catch things like actions that aren't pinned to a hash
46- - advanced-security/codeql-javascript
47- paths:
48- - '.github/workflows'
49- - '.github/actions'
50- - uses : github/codeql-action/analyze@df32e399139a3050671466d7d9b3cbacc1cfd034 # v2.22.8
41+ languages : actions
42+ - uses : github/codeql-action/analyze@3c3833e0f8c1c83d449a7478aa59c036a9165498 # v3.29.11
0 commit comments