mirror of https://github.com/shirou/gopsutil
Ref actions by commit SHA in sbom_generator.yml
It's important to make sure the SHA's are from the original repositories and not forks. For reference: https://github.com/actions/checkout/releases/tag/v3.5.2pull/1480/head8e5e7e5ab8
https://github.com/advanced-security/sbom-generator-action/releases/tag/v0.0.1375dee8e61
https://github.com/actions/upload-artifact/releases/tag/v3.1.20b7f8abb15
Signed-off-by: Gabriela Gutierrez <gabigutierrez@google.com>
parent
f6afa2b95f
commit
346f7bc0fd
Loading…
Reference in New Issue