diff --git a/.github/workflows/code-analysis.yml b/.github/workflows/code-analysis.yml index 72d7a62..2747ec3 100644 --- a/.github/workflows/code-analysis.yml +++ b/.github/workflows/code-analysis.yml @@ -42,13 +42,13 @@ jobs: echo "::endgroup::" - name: Initialize CodeQL - uses: github/codeql-action/init@v2 + uses: github/codeql-action/init@v3 with: languages: ${{ matrix.language }} setup-python-dependencies: false - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@v2 + uses: github/codeql-action/analyze@v3 - name: Run pip audit uses: pypa/gh-action-pip-audit@v1.0.8 @@ -66,7 +66,7 @@ jobs: SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} - name: Upload Snyk runtime dependencies scan result to GitHub Code Scanning - uses: github/codeql-action/upload-sarif@v2 + uses: github/codeql-action/upload-sarif@v3 with: sarif_file: snyk-requirements-${{ matrix.python-version }}.sarif category: requirements-runtime-${{ matrix.python-version }} @@ -78,7 +78,7 @@ jobs: SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} - name: Upload Snyk development dependencies scan result to GitHub Code Scanning - uses: github/codeql-action/upload-sarif@v2 + uses: github/codeql-action/upload-sarif@v3 with: sarif_file: snyk-requirements-dev-${{ matrix.python-version }}.sarif category: requirements-dev-${{ matrix.python-version }}