1616
1717 steps :
1818 - name : Check out repo
19- uses : actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
19+ uses : actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
2020
2121 - name : Set up .NET
2222 uses : actions/setup-dotnet@d4c94342e560b34958eacfc5d055d21461ed1c5d # v5.0.0
3333 ls -atlh ../../../
3434
3535 - name : Upload project artifact
36- uses : actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # v4.4.3
36+ uses : actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
3737 with :
3838 name : KeyConnector.zip
3939 path : src/KeyConnector/KeyConnector.zip
5151 _PROJECT_NAME : key-connector
5252 steps :
5353 - name : Check out repo
54- uses : actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
54+ uses : actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
5555
5656 - name : Log in to Azure
5757 uses : bitwarden/gh-actions/azure-login@main
9090
9191 - name : Build Docker image
9292 id : build-docker
93- uses : docker/build-push-action@4f58ea79222b3b9dc2c8bbdd6debcef730109a75 # v6.9 .0
93+ uses : docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18 .0
9494 with :
9595 context : src/KeyConnector
9696 file : src/KeyConnector/Dockerfile
@@ -100,7 +100,7 @@ jobs:
100100
101101 - name : Install Cosign
102102 if : github.event_name != 'pull_request' && github.ref == 'refs/heads/main'
103- uses : sigstore/cosign-installer@dc72c7d5c4d10cd6bcb8cf6e3fd625a9e5e537da # v3.7 .0
103+ uses : sigstore/cosign-installer@d7543c93d881b35a8faa02e8e3605f69b7a1ce62 # v3.10 .0
104104
105105 - name : Sign image with Cosign
106106 if : github.event_name != 'pull_request' && github.ref == 'refs/heads/main'
@@ -117,7 +117,7 @@ jobs:
117117
118118 - name : Scan Docker image
119119 id : container-scan
120- uses : anchore/scan-action@2c901ab7378897c01b8efaa2d0c9bf519cc64b9e # v6.2.0
120+ uses : anchore/scan-action@1638637db639e0ade3258b51db49a9a137574c3e # v6.5.1
121121 with :
122122 image : ${{ steps.image-name.outputs.name }}
123123 fail-build : false
@@ -127,7 +127,7 @@ jobs:
127127 uses : bitwarden/gh-actions/azure-logout@main
128128
129129 - name : Upload Grype results to GitHub
130- uses : github/codeql-action/upload-sarif@f779452ac5af1c261dce0346a8f964149f49322b # v3.26.13
130+ uses : github/codeql-action/upload-sarif@192325c86100d080feab897ff886c34abd4c83a3 # v3.30.3
131131 with :
132132 sarif_file : ${{ steps.container-scan.outputs.sarif }}
133133 sha : ${{ contains(github.event_name, 'pull_request') && github.event.pull_request.head.sha || github.sha }}
0 commit comments