diff --git a/.github/workflows/periodic-zizmor.yaml b/.github/workflows/periodic-zizmor.yaml index 4bbc43c8..c7c9a2d9 100644 --- a/.github/workflows/periodic-zizmor.yaml +++ b/.github/workflows/periodic-zizmor.yaml @@ -36,7 +36,7 @@ jobs: steps: - name: Checkout - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5 + uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5 with: persist-credentials: false @@ -47,7 +47,7 @@ jobs: github_app: grafana-zizmor-bot - name: Checkout Target - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5 + uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5 with: repository: ${{ matrix.repository.owner }}/${{ matrix.repository.repo }} token: ${{ steps.get-github-app-token.outputs.token }} diff --git a/.github/workflows/self-zizmor.yaml b/.github/workflows/self-zizmor.yaml index 6ed40059..9124a944 100644 --- a/.github/workflows/self-zizmor.yaml +++ b/.github/workflows/self-zizmor.yaml @@ -20,7 +20,7 @@ jobs: found-files: ${{ steps.zizmor-check.outputs.found-files }} steps: - name: Checkout - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5 + uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5 - name: Run zizmor id: zizmor-check shell: bash diff --git a/.github/workflows/snyk_monitor.yml b/.github/workflows/snyk_monitor.yml index fee50b80..373db6e4 100644 --- a/.github/workflows/snyk_monitor.yml +++ b/.github/workflows/snyk_monitor.yml @@ -10,7 +10,7 @@ jobs: runs-on: ubuntu-latest steps: - - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5 + - uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5 with: persist-credentials: false - name: Run Snyk to import ${{ github.event.repository.name }} to Snyk