diff --git a/.github/workflows/build_and_push.yml b/.github/workflows/build_and_push.yml index 832e4a33..d10686d5 100644 --- a/.github/workflows/build_and_push.yml +++ b/.github/workflows/build_and_push.yml @@ -59,7 +59,7 @@ jobs: - name: Login to ECR id: login-ecr - uses: aws-actions/amazon-ecr-login@5a88a04c91d5c6f97aae0d9be790e64d9b1d47b7 # v1.7.1 + uses: aws-actions/amazon-ecr-login@062b18b96a7aff071d4dc91bc00c4c1a7945b076 # v2.0.1 - name: Push containers to ECR run: | diff --git a/.github/workflows/docker_vulnerability_scan.yml b/.github/workflows/docker_vulnerability_scan.yml index ceb54682..8511dae0 100644 --- a/.github/workflows/docker_vulnerability_scan.yml +++ b/.github/workflows/docker_vulnerability_scan.yml @@ -27,7 +27,7 @@ jobs: - name: Login to ECR id: login-ecr - uses: aws-actions/amazon-ecr-login@5a88a04c91d5c6f97aae0d9be790e64d9b1d47b7 # v1.7.1 + uses: aws-actions/amazon-ecr-login@062b18b96a7aff071d4dc91bc00c4c1a7945b076 # v2.0.1 - name: Docker vulnerability scan uses: cds-snc/security-tools/.github/actions/docker-scan@d6bb182e15f0cad80e7625887ae88e5830728aab # v3.0.0