diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 3fd0947..a285b9c 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -31,7 +31,7 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Initialize CodeQL - uses: github/codeql-action/init@5595ccaf912efad79be6eef63a5619ff05969be3 # v4.37.6 + uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 with: languages: javascript-typescript queries: security-and-quality @@ -39,6 +39,6 @@ jobs: # No build step: CodeQL analyses the TypeScript sources directly. Building # the extension would only add the bundled output, which it cannot use. - name: Perform CodeQL analysis - uses: github/codeql-action/analyze@5595ccaf912efad79be6eef63a5619ff05969be3 # v4.37.6 + uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 with: category: "/language:javascript-typescript" diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 9769399..bdee2d4 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -328,7 +328,7 @@ jobs: build/artifacts/*-${{ env.PT_ARTIFACT_VERSION_LABEL }}-source.zip - name: Publish GitHub stable release - uses: softprops/action-gh-release@3d0d9888cb7fd7b750713d6e236d1fcb99157228 # v3 + uses: softprops/action-gh-release@efb35369e0ad2afab669f228072c1b0d510eae64 # v3 with: tag_name: ${{ env.RELEASE_TAG }} body_path: build/artifacts/release-notes.md @@ -488,7 +488,7 @@ jobs: build/artifacts/beta-release-notes.md - name: Publish GitHub beta prerelease - uses: softprops/action-gh-release@3d0d9888cb7fd7b750713d6e236d1fcb99157228 # v3 + uses: softprops/action-gh-release@efb35369e0ad2afab669f228072c1b0d510eae64 # v3 with: token: ${{ steps.app_token.outputs.token || github.token }} tag_name: ${{ env.BETA_TAG }}