diff --git a/workflow-templates/dependency-review.yaml b/workflow-templates/dependency-review.yaml index f362ab3..8f7127d 100644 --- a/workflow-templates/dependency-review.yaml +++ b/workflow-templates/dependency-review.yaml @@ -22,7 +22,7 @@ jobs: run: echo "first_commit_sha=$(git rev-list --max-parents=0 HEAD)" >> $GITHUB_ENV - name: 'Dependency Review (manual)' if: github.event_name == 'workflow_dispatch' - uses: actions/dependency-review-action@3c4e3dcb1aa7874d2c16be7d79418e9b7efd6261 # v4.8.2 + uses: actions/dependency-review-action@05fe4576374b728f0c523d6a13d64c25081e0803 # v4.8.3 with: base-ref: ${{ env.first_commit_sha }} head-ref: ${{ github.ref }} @@ -32,7 +32,7 @@ jobs: warn-only: true - name: 'Dependency Review (pull_request)' if: github.event_name == 'pull_request' - uses: actions/dependency-review-action@3c4e3dcb1aa7874d2c16be7d79418e9b7efd6261 # v4.8.2 + uses: actions/dependency-review-action@05fe4576374b728f0c523d6a13d64c25081e0803 # v4.8.3 with: show-openssf-scorecard: true vulnerability-check: true