diff --git a/.github/workflows/analysis.yml b/.github/workflows/analysis.yml index 1f13e3b..b4a52cc 100644 --- a/.github/workflows/analysis.yml +++ b/.github/workflows/analysis.yml @@ -34,13 +34,13 @@ jobs: - language: "python" steps: - uses: actions/checkout@v4 - - uses: github/codeql-action/init@v2 + - uses: github/codeql-action/init@v3 with: languages: ${{ matrix.language }} - name: Autobuild if: ${{ ! matrix.build }} - uses: github/codeql-action/autobuild@v2 + uses: github/codeql-action/autobuild@v3 - uses: actions/setup-java@v4 if: ${{ matrix.build && matrix.language == 'java' }} @@ -62,7 +62,7 @@ jobs: working-directory: ${{ matrix.working-directory }} - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@v2 + uses: github/codeql-action/analyze@v3 with: category: "/language:${{matrix.language}}" @@ -85,7 +85,7 @@ jobs: severity: "CRITICAL,HIGH" - name: Upload Trivy scan results to GitHub Security tab - uses: github/codeql-action/upload-sarif@v2 + uses: github/codeql-action/upload-sarif@v3 with: sarif_file: "trivy-results.sarif"