diff --git a/.github/actions/docker-scan/action.yml b/.github/actions/docker-scan/action.yml index 8c85ed72..b9688619 100644 --- a/.github/actions/docker-scan/action.yml +++ b/.github/actions/docker-scan/action.yml @@ -33,7 +33,7 @@ runs: shell: bash - name: Upload trivy scan results to github security tab - uses: github/codeql-action/upload-sarif@0b21cf2492b6b02c465a3e5d7c473717ad7721ba # v3.23.1 + uses: github/codeql-action/upload-sarif@b7bf0a3ed3ecfa44160715d7c442788f65f0f923 # v3.23.2 with: sarif_file: "trivy-results.sarif" token: ${{ inputs.token }} diff --git a/.github/workflows/base-terragrunt-plan.yml b/.github/workflows/base-terragrunt-plan.yml index 48511c2b..10de502c 100644 --- a/.github/workflows/base-terragrunt-plan.yml +++ b/.github/workflows/base-terragrunt-plan.yml @@ -55,7 +55,7 @@ jobs: - name: Terragrunt plan base if: ${{ steps.filter.outputs.base == 'true' || steps.filter.outputs.common == 'true' }} - uses: cds-snc/terraform-plan@b84f6e89f3e7b5ecf648a2c036c043c73d82da59 # v3.1.0 + uses: cds-snc/terraform-plan@5311f3dac704235dde778e30fa7d2bd0c0d8036f # v3.2.0 with: directory: "terragrunt/env/base" comment-delete: "true" diff --git a/.github/workflows/build_and_push.yml b/.github/workflows/build_and_push.yml index 14256f30..2aa8d29e 100644 --- a/.github/workflows/build_and_push.yml +++ b/.github/workflows/build_and_push.yml @@ -28,7 +28,7 @@ jobs: - name: Checkout uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1 - - uses: dorny/paths-filter@4512585405083f25c027a35db413c2b3b9006d50 # tag=v2.11.1 + - uses: dorny/paths-filter@7267a8516b6f92bdb098633497bad573efdbf271 # v2.12.0 id: filter with: filters: | diff --git a/.github/workflows/ci_build_containers.yml b/.github/workflows/ci_build_containers.yml index b5e6e754..9c4878a4 100644 --- a/.github/workflows/ci_build_containers.yml +++ b/.github/workflows/ci_build_containers.yml @@ -27,7 +27,7 @@ jobs: - name: Checkout uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1 - - uses: dorny/paths-filter@4512585405083f25c027a35db413c2b3b9006d50 # tag=v2.11.1 + - uses: dorny/paths-filter@7267a8516b6f92bdb098633497bad573efdbf271 # v2.12.0 id: filter with: filters: | diff --git a/.github/workflows/ci_tools.yml b/.github/workflows/ci_tools.yml index b0f63d4b..c6855d40 100644 --- a/.github/workflows/ci_tools.yml +++ b/.github/workflows/ci_tools.yml @@ -14,7 +14,7 @@ jobs: - name: Checkout uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1 - - uses: dorny/paths-filter@4512585405083f25c027a35db413c2b3b9006d50 # tag=v2.11.1 + - uses: dorny/paths-filter@7267a8516b6f92bdb098633497bad573efdbf271 # v2.12.0 id: filter with: filters: | diff --git a/.github/workflows/cloud-asset-inventory-terragrunt-plan.yml b/.github/workflows/cloud-asset-inventory-terragrunt-plan.yml index cb7f94b0..eb189e0e 100644 --- a/.github/workflows/cloud-asset-inventory-terragrunt-plan.yml +++ b/.github/workflows/cloud-asset-inventory-terragrunt-plan.yml @@ -60,7 +60,7 @@ jobs: - name: Terragrunt plan cloud_asset_inventory if: ${{ steps.filter.outputs.cloud_asset_inventory == 'true' || steps.filter.outputs.common == 'true' }} - uses: cds-snc/terraform-plan@b84f6e89f3e7b5ecf648a2c036c043c73d82da59 # v3.1.0 + uses: cds-snc/terraform-plan@5311f3dac704235dde778e30fa7d2bd0c0d8036f # v3.2.0 with: directory: "terragrunt/env/cloud_asset_inventory" comment-delete: "true" diff --git a/.github/workflows/csp-reports-terragrunt-plan.yml b/.github/workflows/csp-reports-terragrunt-plan.yml index ba2003b8..945aa4d1 100644 --- a/.github/workflows/csp-reports-terragrunt-plan.yml +++ b/.github/workflows/csp-reports-terragrunt-plan.yml @@ -57,7 +57,7 @@ jobs: - name: Terragrunt plan csp_violation_report_service if: ${{ steps.filter.outputs.csp_violation_report_service == 'true' || steps.filter.outputs.common == 'true' }} - uses: cds-snc/terraform-plan@b84f6e89f3e7b5ecf648a2c036c043c73d82da59 # v3.1.0 + uses: cds-snc/terraform-plan@5311f3dac704235dde778e30fa7d2bd0c0d8036f # v3.2.0 with: directory: "terragrunt/env/csp_violation_report_service" comment-delete: "true"