This is an automated email from the ASF dual-hosted git repository.
jacopoc pushed a commit to branch trunk
in repository https://gitbox.apache.org/repos/asf/ofbiz-framework.git
The following commit(s) were added to refs/heads/trunk by this push:
new 52860a7fb6 Bump github/codeql-action/upload-sarif
52860a7fb6 is described below
commit 52860a7fb6b39537df736559a716bf8c9aa52334
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
AuthorDate: Tue Jul 7 13:37:26 2026 +0000
Bump github/codeql-action/upload-sarif
Bumps
[github/codeql-action/upload-sarif](https://github.com/github/codeql-action)
from ae4c8d057d67a1b17026d584ad10186562334d21 to
006d029c8dc7b906d4ce5b7c700d32f20f2d35dd.
- [Release notes](https://github.com/github/codeql-action/releases)
-
[Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
-
[Commits](https://github.com/github/codeql-action/compare/ae4c8d057d67a1b17026d584ad10186562334d21...006d029c8dc7b906d4ce5b7c700d32f20f2d35dd)
---
updated-dependencies:
- dependency-name: github/codeql-action/upload-sarif
dependency-version: 006d029c8dc7b906d4ce5b7c700d32f20f2d35dd
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <[email protected]>
---
.github/workflows/scorecard.yml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml
index de9803321a..e40daafb1f 100644
--- a/.github/workflows/scorecard.yml
+++ b/.github/workflows/scorecard.yml
@@ -103,6 +103,6 @@ jobs:
# Upload the results to GitHub's code scanning dashboard.
- name: "Upload to code-scanning"
if: ${{ !env.ACT }}
- uses:
github/codeql-action/upload-sarif@ae4c8d057d67a1b17026d584ad10186562334d21 #
v2.16.2
+ uses:
github/codeql-action/upload-sarif@006d029c8dc7b906d4ce5b7c700d32f20f2d35dd #
v2.16.2
with:
sarif_file: results.sarif