diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 7fd50bd0de8..7c4404027af 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -38,7 +38,7 @@ jobs: persist-credentials: false - name: "Run analysis" - uses: ossf/scorecard-action@62b2cac7ed8198b15735ed49ab1e5cf35480ba46 # v2.4.0 + uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3 with: results_file: results.sarif results_format: sarif diff --git a/.github/workflows/website.yml b/.github/workflows/website.yml index a405f164dcc..f66122d46ba 100644 --- a/.github/workflows/website.yml +++ b/.github/workflows/website.yml @@ -50,7 +50,7 @@ jobs: run: (cd website && yarn build) - name: Deploy - uses: JamesIves/github-pages-deploy-action@15de0f09300eea763baee31dff6c6184995c5f6a # 4.7.2 + uses: JamesIves/github-pages-deploy-action@6c2d9db40f9296374acc17b90404b6e8864128c8 # 4.7.3 with: token: ${{ secrets.WEBSITE_DEPLOY_TOKEN }} branch: gh-pages