diff --git a/.github/workflows/maven-service-build.yml b/.github/workflows/maven-service-build.yml index 14a44b2..2534699 100644 --- a/.github/workflows/maven-service-build.yml +++ b/.github/workflows/maven-service-build.yml @@ -74,6 +74,6 @@ jobs: run: trivy sbom --severity CRITICAL,HIGH --format sarif -o trivy-report.sarif ./bom.json - name: Upload SARIF report - uses: github/codeql-action/upload-sarif@v3 + uses: github/codeql-action/upload-sarif@v4 with: sarif_file: trivy-report.sarif diff --git a/.github/workflows/semgrep-scan.yml b/.github/workflows/semgrep-scan.yml index 6beb59e..4986543 100644 --- a/.github/workflows/semgrep-scan.yml +++ b/.github/workflows/semgrep-scan.yml @@ -26,7 +26,7 @@ jobs: path: semgrep.sarif - name: Scanning alerts - uses: github/codeql-action/upload-sarif@v3.28.8 + uses: github/codeql-action/upload-sarif@v4.32.0 with: sarif_file: semgrep.sarif category: semgrep