Skip to content

Commit 32c8d78

Browse files
committed
gh-actions: codeql v4
1 parent ed644de commit 32c8d78

3 files changed

Lines changed: 13 additions & 6 deletions

File tree

.github/workflows/codeql.yml

Lines changed: 10 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -50,15 +50,15 @@ jobs:
5050

5151
# Initializes the CodeQL tools for scanning.
5252
- name: 🛠️ Initialize
53-
uses: github/codeql-action/init@v3
53+
uses: github/codeql-action/init@v4
5454
with:
5555
languages: ${{ matrix.language }}
5656
# If you wish to specify custom queries, you can do so here or in a config file.
5757
# By default, queries listed here will override any specified in a config file.
5858
# Prefix the list here with "+" to use these queries and those in the config file.
5959

6060
# For more details on CodeQL's query packs, refer to: https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning#using-queries-in-ql-packs
61-
# queries: security-extended,security-and-quality
61+
queries: security-extended,security-and-quality
6262

6363

6464
# Autobuild attempts to build any compiled languages (C/C++, C#, Go, Java, or Swift).
@@ -78,6 +78,13 @@ jobs:
7878
shell: bash
7979

8080
- name: 🧩 Perform CodeQL
81-
uses: github/codeql-action/analyze@v3
81+
uses: github/codeql-action/analyze@v4
8282
with:
8383
category: "/language:${{matrix.language}}"
84+
85+
# docs.github.com/en/code-security/code-scanning/integrating-with-code-scanning/uploading-a-sarif-file-to-github
86+
- name: 📡 Upload to code-scanning
87+
uses: github/codeql-action/upload-sarif@v4
88+
with:
89+
# Path to SARIF file relative to the root of the repository
90+
sarif_file: results.sarif

.github/workflows/go.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -343,7 +343,7 @@ jobs:
343343
# severity-cutoff: critical
344344

345345
- name: 📻 Grype to code-scanning
346-
uses: github/codeql-action/upload-sarif@v3
346+
uses: github/codeql-action/upload-sarif@v4
347347
with:
348348
sarif_file: ${{ steps.scan.outputs.sarif }}
349349

@@ -390,7 +390,7 @@ jobs:
390390
# we let the report trigger content trigger a failure using the GitHub Security features.
391391
args: '-no-fail -fmt sarif -out results.sarif ./...'
392392
- name: 📡 Upload to code-scanning
393-
uses: github/codeql-action/upload-sarif@v3
393+
uses: github/codeql-action/upload-sarif@v4
394394
with:
395395
sarif_file: results.sarif
396396

.github/workflows/scorecard.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -67,6 +67,6 @@ jobs:
6767

6868
# Upload the results to GitHub's code scanning dashboard.
6969
- name: ⛳️ Upload to code-scanning
70-
uses: github/codeql-action/upload-sarif@v3.28.16
70+
uses: github/codeql-action/upload-sarif@v4
7171
with:
7272
sarif_file: results.sarif

0 commit comments

Comments
 (0)