diff --git a/.github/workflows/security-scan.yml b/.github/workflows/security-scan.yml index 69ad705..dd96ae8 100644 --- a/.github/workflows/security-scan.yml +++ b/.github/workflows/security-scan.yml @@ -29,7 +29,7 @@ jobs: actions: read contents: read security-events: write - uses: google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml@8deb546fdb875b9996d27d4950be7312dac076a1 # v2.5.0 + uses: google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml@6e4298ebc4db23e847df9b2e2de2939d6f066c67 # v2.5.1 with: # Scan the committed lockfiles rather than the whole tree: they are the # complete, resolved dependency set for the package and the docs site.