Commit ced8a18
semgrep workflow: pin Docker image and actions to version tags
Pin returntocorp/semgrep container image to a specific version
and GitHub Actions to major version tags to prevent :latest
tag resolution and reduce supply-chain attack surface.
Fixes: LCNC-15821
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>1 parent 4a6697b commit ced8a18
1 file changed
Lines changed: 1 addition & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
27 | 27 | | |
28 | 28 | | |
29 | 29 | | |
30 | | - | |
31 | | - | |
| 30 | + | |
32 | 31 | | |
33 | 32 | | |
34 | 33 | | |
| |||
0 commit comments