Skip to content

Commit 8fcf967

Browse files
ci: pin gosec action to specific version (#399)
Updated gosec action to a specific version for consistency.
1 parent 2d6ac63 commit 8fcf967

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

.github/workflows/pull-request.yaml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -42,17 +42,17 @@ jobs:
4242
path: "main"
4343
- name: Run gosec on main
4444
if: github.event_name == 'pull_request'
45-
uses: securego/gosec@master
45+
uses: securego/gosec@6be2b51fd78feca86af91f5186b7964d76cb1256 # v2.22.10
4646
with:
4747
args: '-no-fail -fmt sarif -out results.sarif -tests -ai-api-provider="none" ./...'
4848
- name: Run gosec on PR
4949
if: github.event_name == 'pull_request'
50-
uses: securego/gosec@master
50+
uses: securego/gosec@6be2b51fd78feca86af91f5186b7964d76cb1256 # v2.22.10
5151
with:
5252
args: '-no-fail -fmt sarif -out results.sarif -tests -ai-api-provider="none" ./...'
5353
- name: Run gosec on push
5454
if: github.event_name != 'pull_request'
55-
uses: securego/gosec@master
55+
uses: securego/gosec@6be2b51fd78feca86af91f5186b7964d76cb1256 # v2.22.10
5656
with:
5757
args: '-no-fail -fmt sarif -out results.sarif -tests -ai-api-provider="none" ./...'
5858
- name: Upload SARIF file

0 commit comments

Comments
 (0)