Since actions are referenced by commit SHA, it's important to make sure the SHA's are from the original repositories and not forks. For reference: https://github.com/actions/checkout/releases/tag/v3.5.3 https://github.com/actions/checkout/commit/c85c95e3d7251135ab7dc9ce3241c5835cc595a9 https://github.com/ossf/scorecard-action/releases/tag/v2.2.0 https://github.com/ossf/scorecard-action/commit/08b4669551908b1024bb425080c797723083c031 https://github.com/actions/upload-artifact/releases/tag/v3.1.2 https://github.com/actions/upload-artifact/commit/0b7f8abb1508181956e8e162db84b466c27e18ce https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.14.2 https://github.com/github/codeql-action/commit/f9a7c6738f28efb36e31d49c53a201a9c5d6a476 Signed-off-by: Gabriela Gutierrez <gabigutierrez@google.com>