diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index f7f28d7..2797308 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -64,7 +64,7 @@ jobs: scanners: 'vuln' # Only scan vulnerabilities, not secrets (avoids false positives in vendored gems) - name: Upload Trivy results to GitHub Security tab - uses: github/codeql-action/upload-sarif@v3 + uses: github/codeql-action/upload-sarif@v4 if: always() with: sarif_file: 'trivy-results.sarif'