diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 35e5cb18..b746717c 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -15,7 +15,7 @@ jobs: ruby: ['3.2', '3.1', '3.0', '2.7', jruby, truffleruby, debug] continue-on-error: ${{ endsWith(matrix.ruby, 'head') || matrix.ruby == 'debug' }} steps: - - uses: actions/checkout@v3 + - uses: actions/checkout@v4 - run: rm Gemfile.lock - name: Setup Ruby ${{ matrix.ruby }} uses: ruby/setup-ruby@v1 @@ -31,7 +31,7 @@ jobs: env: CC_TEST_REPORTER_ID: ${{ secrets.CC_TEST_REPORTER_ID }} steps: - - uses: actions/checkout@v3 + - uses: actions/checkout@v4 - uses: ruby/setup-ruby@v1 with: bundler-cache: true @@ -70,7 +70,7 @@ jobs: lint: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v3 + - uses: actions/checkout@v4 - uses: ruby/setup-ruby@v1 with: bundler-cache: true @@ -85,7 +85,7 @@ jobs: runs-on: ubuntu-latest continue-on-error: true steps: - - uses: actions/checkout@v3 + - uses: actions/checkout@v4 - name: Check markdown files for broken links uses: justinbeckwith/linkinator-action@v1 with: diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 62ca147e..46cf1004 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -22,7 +22,7 @@ jobs: language: [ 'ruby' ] steps: - name: Checkout repository - uses: actions/checkout@v3 + uses: actions/checkout@v4 - name: Initialize CodeQL uses: github/codeql-action/init@v2 with: @@ -45,7 +45,7 @@ jobs: steps: # Checkout the repository to the GitHub Actions runner - name: Checkout code - uses: actions/checkout@v3 + uses: actions/checkout@v4 # Execute Codacy Analysis CLI and generate a SARIF output with the security issues identified during the analysis - name: Run Codacy Analysis CLI @@ -76,7 +76,7 @@ jobs: image: returntocorp/semgrep steps: - name: Checkout repository - uses: actions/checkout@v3 + uses: actions/checkout@v4 - name: Semgrep Scan run: semgrep scan --config=auto --sarif --output=semgrep.sarif env: @@ -94,7 +94,7 @@ jobs: if: (github.actor != 'dependabot[bot]') steps: - name: Checkout repository - uses: actions/checkout@v3 + uses: actions/checkout@v4 - name: Run Snyk to check for vulnerabilities uses: snyk/actions/ruby@master continue-on-error: true @@ -113,7 +113,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout repository - uses: actions/checkout@v3 + uses: actions/checkout@v4 - name: Analyze the licences with Fossa uses: fossas/fossa-action@main with: