Merge pull request #61 from apache/dependabot/github_actions/github/codeql-action-2.3.5

Bump github/codeql-action from 2.3.3 to 2.3.5
diff --git a/.github/workflows/scorecards-analysis.yml b/.github/workflows/scorecards-analysis.yml
index 904303a..ca62cc4 100644
--- a/.github/workflows/scorecards-analysis.yml
+++ b/.github/workflows/scorecards-analysis.yml
@@ -64,6 +64,6 @@
           retention-days: 5
 
       - name: "Upload to code-scanning"
-        uses: github/codeql-action/upload-sarif@29b1f65c5e92e24fe6b6647da1eaabe529cec70f    # 2.3.3
+        uses: github/codeql-action/upload-sarif@0225834cc549ee0ca93cb085b92954821a145866    # 2.3.5
         with:
           sarif_file: results.sarif