diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 7dcd00b..6b77b29 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -32,7 +32,7 @@ jobs: repo_token: ${{ secrets.SCORECARD_TOKEN || secrets.GITHUB_TOKEN }} - name: Upload Scorecard results to GitHub Security tab - uses: github/codeql-action/upload-sarif@a60c4df7a135c7317c1e9ddf9b5a9b07a910dda9 # v4 + uses: github/codeql-action/upload-sarif@v4 # tag required by scorecard webapp verification with: sarif_file: results.sarif category: scorecard