fix: use tag for codeql-action in scorecard (webapp rejects SHA pins)

This commit is contained in:
2026-03-19 10:42:14 +00:00
parent 4ec963d41c
commit 07aed45518

View File

@@ -32,7 +32,7 @@ jobs:
repo_token: ${{ secrets.SCORECARD_TOKEN || secrets.GITHUB_TOKEN }} repo_token: ${{ secrets.SCORECARD_TOKEN || secrets.GITHUB_TOKEN }}
- name: Upload Scorecard results to GitHub Security tab - name: Upload Scorecard results to GitHub Security tab
uses: github/codeql-action/upload-sarif@a60c4df7a135c7317c1e9ddf9b5a9b07a910dda9 # v4 uses: github/codeql-action/upload-sarif@v4 # tag required by scorecard webapp verification
with: with:
sarif_file: results.sarif sarif_file: results.sarif
category: scorecard category: scorecard