diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index ddc14a6..9ee3d05 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -40,7 +40,7 @@ jobs: steps: - name: "Harden Runner" - uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0 + uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4 with: disable-sudo-and-containers: false # MAINTAINER CHOICE: Use "audit" first to discover needed endpoints,