@@ -19,11 +19,11 @@ jobs:
1919 pull-requests : read
2020 runs-on : ubuntu-latest
2121 steps :
22- - uses : actions/checkout@v4
22+ - uses : actions/checkout@ff7abcd0c3c05ccf6adc123a8cd1fd4fb30fb493
2323 with : { fetch-depth: 2 }
2424 - name : Dependency review
2525 id : dr
26- uses : actions/dependency-review-action@v4
26+ uses : actions/dependency-review-action@6fad41793215e16e31faa120c584d320a07b88de
2727 with :
2828 fail-on-severity : high
2929 # Clave: fuera de PR, no romper el job aunque detecte problemas
@@ -37,11 +37,11 @@ jobs:
3737 security-events : write
3838 runs-on : ubuntu-latest
3939 steps :
40- - uses : actions/checkout@v4
40+ - uses : actions/checkout@ff7abcd0c3c05ccf6adc123a8cd1fd4fb30fb493
4141 with : { fetch-depth: 0 }
4242 - name : Run Scorecard
4343 id : scorecard
44- uses : ossf/scorecard-action@v2 .3.3
44+ uses : ossf/scorecard-action@43e475b79a8bd5217334edc08879005b2229d79a .3.3
4545 with :
4646 results_file : results.sarif
4747 results_format : sarif
@@ -55,14 +55,14 @@ jobs:
5555 permissions : { contents: read }
5656 runs-on : ubuntu-latest
5757 steps :
58- - uses : actions/checkout@v4
58+ - uses : actions/checkout@ff7abcd0c3c05ccf6adc123a8cd1fd4fb30fb493
5959 - name : Generate SBOM (SPDX)
60- uses : anchore/sbom-action@v0 .17.6
60+ uses : anchore/sbom-action@c73dd3f93ab542b7902df62a6ee5ad763179fa7b .17.6
6161 with :
6262 format : spdx-json
6363 output-file : sbom.spdx.json
6464 - name : Upload SBOM artifact
65- uses : actions/upload-artifact@v4
65+ uses : actions/upload-artifact@de65e23aa2b7e23d713bb51fbfcb6d502f8667d8
6666 with :
6767 name : sbom-spdx
6868 path : sbom.spdx.json
0 commit comments