diff --git a/.github/workflows/runs-on.yml b/.github/workflows/runs-on.yml index 319b915..a233b74 100644 --- a/.github/workflows/runs-on.yml +++ b/.github/workflows/runs-on.yml @@ -3,6 +3,9 @@ name: RunsOn Tests on: workflow_dispatch: +permissions: + contents: read + jobs: test-host-outbound: runs-on: diff --git a/.github/workflows/scorecards.yml b/.github/workflows/scorecards.yml index e694a29..f5deaae 100644 --- a/.github/workflows/scorecards.yml +++ b/.github/workflows/scorecards.yml @@ -54,7 +54,7 @@ jobs: # Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF # format to the repository Actions tab. - name: "Upload artifact" - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # tag=v3.0.0 + uses: actions/upload-artifact@4cec3d8aa04e39d1a68397de0c4cd6fb9dce8ec1 # tag=v4.6.1 with: name: SARIF file path: results.sarif