From 7e02a62b978b2717914a9abb1562fd90ba6a7b0c Mon Sep 17 00:00:00 2001 From: WRG-11 <281155251+WRG-11@users.noreply.github.com> Date: Thu, 4 Jun 2026 06:32:21 +0300 Subject: [PATCH] fix(ci): pin codeql-action/checkout refs to commit SHA (R89-182f) Mutable tag -> immutable SHA pin (supply-chain hardening). No workflow logic changed. Author: WRG-11 <281155251+WRG-11@users.noreply.github.com> --- .github/workflows/codeql.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 00a2652..634fa2b 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -33,13 +33,13 @@ jobs: echo "languages=$langs" >> "$GITHUB_OUTPUT" - name: Initialize CodeQL - uses: github/codeql-action/init@v4 + uses: github/codeql-action/init@87557b9c84dde89fdd9b10e88954ac2f4248e463 # v4.36.1 with: languages: ${{ steps.detect.outputs.languages }} - name: Autobuild - uses: github/codeql-action/autobuild@v4 + uses: github/codeql-action/autobuild@87557b9c84dde89fdd9b10e88954ac2f4248e463 # v4.36.1 - name: Analyze - uses: github/codeql-action/analyze@v4 + uses: github/codeql-action/analyze@87557b9c84dde89fdd9b10e88954ac2f4248e463 # v4.36.1