diff --git a/.github/workflows/default.yml b/.github/workflows/default.yml index eeca1eb9..ef055dc4 100644 --- a/.github/workflows/default.yml +++ b/.github/workflows/default.yml @@ -41,7 +41,7 @@ jobs: run: cp .github/workflows/config/settings.xml ${HOME}/.m2/settings.xml - name: Initialize CodeQL - uses: github/codeql-action/init@v3.24.4 + uses: github/codeql-action/init@v3.24.6 with: languages: java queries: security-and-quality @@ -60,7 +60,7 @@ jobs: NEXUS_GITHUB_ACTIONS_READONLY_TOKEN: ${{ secrets.NEXUS_GITHUB_ACTIONS_READONLY_TOKEN }} - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@v3.24.4 + uses: github/codeql-action/analyze@v3.24.6 with: category: '/language:java' @@ -75,7 +75,7 @@ jobs: limit-severities-for-sarif: true - name: Upload Trivy scan results to GitHub Security tab - uses: github/codeql-action/upload-sarif@v3.24.4 + uses: github/codeql-action/upload-sarif@v3.24.6 with: sarif_file: trivy-results.sarif