diff --git a/.github/workflows/gitleaks-scanning.yml b/.github/workflows/gitleaks-scanning.yml index f4a1cdc..69f62f7 100644 --- a/.github/workflows/gitleaks-scanning.yml +++ b/.github/workflows/gitleaks-scanning.yml @@ -10,7 +10,7 @@ jobs: name: gitleaks runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v6 with: fetch-depth: 0 - uses: gitleaks/gitleaks-action@v2 diff --git a/.github/workflows/release-goreleaser.yml b/.github/workflows/release-goreleaser.yml index 91b6989..d3a5a80 100644 --- a/.github/workflows/release-goreleaser.yml +++ b/.github/workflows/release-goreleaser.yml @@ -14,7 +14,7 @@ jobs: packages: write # [DOCKER] Required for ghcr.io push id-token: write # [SIGNING] Required for cosign keyless signing steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd + - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 with: fetch-depth: 0 # Full history needed for changelog persist-credentials: false # Avoid exposing token to submodules diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index b5c0065..20aa52f 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -63,7 +63,7 @@ jobs: api.scorecard.dev:443 - name: "Checkout code" - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 with: persist-credentials: false