Skip to content

Commit ab2d3e7

Browse files
authored
ci: Update CodeQL to use actions packs. (#8405)
1 parent 502e393 commit ab2d3e7

File tree

1 file changed

+8
-16
lines changed

1 file changed

+8
-16
lines changed

.github/workflows/codeql-analysis.yaml

Lines changed: 8 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -20,31 +20,23 @@ jobs:
2020
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
2121
- uses: ./.github/actions/install-deps
2222
- run: make vulncheck
23-
- uses: github/codeql-action/init@df32e399139a3050671466d7d9b3cbacc1cfd034 # v2.22.8
23+
- uses: github/codeql-action/init@3c3833e0f8c1c83d449a7478aa59c036a9165498 # v3.29.11
2424
with:
2525
languages: go
26-
- uses: github/codeql-action/autobuild@df32e399139a3050671466d7d9b3cbacc1cfd034 # v2.22.8
27-
- uses: github/codeql-action/analyze@df32e399139a3050671466d7d9b3cbacc1cfd034 # v2.22.8
26+
- uses: github/codeql-action/autobuild@3c3833e0f8c1c83d449a7478aa59c036a9165498 # v3.29.11
27+
- uses: github/codeql-action/analyze@3c3833e0f8c1c83d449a7478aa59c036a9165498 # v3.29.11
2828
# Javascript is added here for evaluating Github Action vulnerabilities
2929
# https://github.blog/2023-08-09-four-tips-to-keep-your-github-actions-workflows-secure/#2-enable-code-scanning-for-workflows
3030
analyze-github-actions:
3131
name: Analyze Github Actions
3232
if: github.repository == 'aws/karpenter-provider-aws'
3333
runs-on: ubuntu-latest
3434
permissions:
35-
actions: read # github/codeql-action/init@v2
36-
security-events: write # github/codeql-action/init@v2
35+
actions: read # github/codeql-action/init@v3
36+
security-events: write # github/codeql-action/init@v3
3737
steps:
3838
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
39-
- uses: github/codeql-action/init@df32e399139a3050671466d7d9b3cbacc1cfd034 # v2.22.8
39+
- uses: github/codeql-action/init@3c3833e0f8c1c83d449a7478aa59c036a9165498 # v3.29.11
4040
with:
41-
languages: javascript
42-
config: |
43-
packs:
44-
# Use the latest version of 'codeql-javascript' published by 'advanced-security'
45-
# This will catch things like actions that aren't pinned to a hash
46-
- advanced-security/codeql-javascript
47-
paths:
48-
- '.github/workflows'
49-
- '.github/actions'
50-
- uses: github/codeql-action/analyze@df32e399139a3050671466d7d9b3cbacc1cfd034 # v2.22.8
41+
languages: actions
42+
- uses: github/codeql-action/analyze@3c3833e0f8c1c83d449a7478aa59c036a9165498 # v3.29.11

0 commit comments

Comments
 (0)