ci: Apply CodeQL workflow fixes #1319
8 new alerts including 8 medium severity security vulnerabilities
New alerts in code changed by this pull request
Security Alerts:
- 8 medium
See annotations below for details.
Annotations
Check warning on line 34 in .github/workflows/deploy-website.yml
Code scanning / CodeQL
Unpinned tag for a non-immutable Action in workflow Medium
uses 'ruby/setup-ruby' with ref 'v1.207.0', not a pinned commit hash
Check warning on line 66 in .github/workflows/deploy-website.yml
Code scanning / CodeQL
Unpinned tag for a non-immutable Action in workflow Medium
uses 'cloudflare/wrangler-action' with ref 'v3.1.0', not a pinned commit hash
Check warning on line 19 in .github/workflows/lint-pull-request.yml
Code scanning / CodeQL
Unpinned tag for a non-immutable Action in workflow Medium
uses 'amannn/action-semantic-pull-request' with ref 'v5.1.0', not a pinned commit hash
Check warning on line 32 in .github/workflows/lint-pull-request.yml
Code scanning / CodeQL
Unpinned tag for a non-immutable Action in workflow Medium
uses 'marocchino/sticky-pull-request-comment' with ref 'v2.1.0', not a pinned commit hash
Check warning on line 81 in .github/workflows/lint-pull-request.yml
Code scanning / CodeQL
Unpinned tag for a non-immutable Action in workflow Medium
uses 'marocchino/sticky-pull-request-comment' with ref 'v2.1.0', not a pinned commit hash
Check warning on line 22 in .github/workflows/lock-issues-pr.yml
Code scanning / CodeQL
Unpinned tag for a non-immutable Action in workflow Medium
uses 'dessant/lock-threads' with ref 'v5.0.1', not a pinned commit hash
Check warning on line 33 in .github/workflows/test-website-a11y.yml
Code scanning / CodeQL
Unpinned tag for a non-immutable Action in workflow Medium test
uses 'ruby/setup-ruby' with ref 'v1.207.0', not a pinned commit hash
Check warning on line 33 in .github/workflows/test-website-links.yml
Code scanning / CodeQL
Unpinned tag for a non-immutable Action in workflow Medium test
uses 'ruby/setup-ruby' with ref 'v1.207.0', not a pinned commit hash