Bump github/codeql-action from 2.1.16 to 2.1.17

Closes https://github.com/dart-lang/sdk/pull/49570

GitOrigin-RevId: 2de884f9e526de9660c047f51bfc0f0aa532d128
Change-Id: I377639c9237b397e25565236a0fc9af43bcc84b5
Reviewed-on: https://dart-review.googlesource.com/c/sdk/+/253300
Reviewed-by: Alexander Thomas <athom@google.com>
diff --git a/.github/workflows/scorecards-analysis.yml b/.github/workflows/scorecards-analysis.yml
index b88605d..7d76584 100644
--- a/.github/workflows/scorecards-analysis.yml
+++ b/.github/workflows/scorecards-analysis.yml
@@ -49,6 +49,6 @@
 
       # Upload the results to GitHub's code scanning dashboard.
       - name: "Upload to code-scanning"
-        uses: github/codeql-action/upload-sarif@3e7e3b32d0fb8283594bb0a76cc60a00918b0969
+        uses: github/codeql-action/upload-sarif@0c670bbf0414f39666df6ce8e718ec5662c21e03
         with:
           sarif_file: results.sarif