Skip to content

Commit

Permalink
Merge pull request nest#2875 from step-security-bot/stepsecurity_reme…
Browse files Browse the repository at this point in the history
…diation_1691510536

Harden GitHub Actions – Harden Runner and pin Actions
  • Loading branch information
gtrensch authored Nov 21, 2023
2 parents 6a9c75b + acde447 commit 3b762d4
Show file tree
Hide file tree
Showing 6 changed files with 173 additions and 41 deletions.
8 changes: 7 additions & 1 deletion .github/workflows/build_dispatch.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,8 +9,14 @@ jobs:
name: "Trigger downstream repos"
runs-on: ubuntu-latest
steps:
- name: Harden Runner
uses: step-security/harden-runner@cba0d00b1fc9a034e1e642ea0f1103c282990604 # v2.5.0
with:
egress-policy: audit
disable-telemetry: true

- name: Trigger nest/nest-extension-module CI
uses: peter-evans/repository-dispatch@v2
uses: peter-evans/repository-dispatch@26b39ed245ab8f31526069329e112ab2fb224588 # v2.1.1
with:
token: ${{ secrets.NEST_EXTENSION_MODULE_TRIGGER_TOKEN }}
repository: 'nest/nest-extension-module'
Expand Down
6 changes: 6 additions & 0 deletions .github/workflows/ebrains-push.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,12 @@ jobs:
runs-on: ubuntu-latest
if: ${{ github.repository_owner == 'nest' }}
steps:
- name: Harden Runner
uses: step-security/harden-runner@cba0d00b1fc9a034e1e642ea0f1103c282990604 # v2.5.0
with:
egress-policy: audit
disable-telemetry: true

- name: sycnmaster
uses: wei/git-sync@55c6b63b4f21607da0e9877ca9b4d11a29fc6d83
with:
Expand Down
6 changes: 6 additions & 0 deletions .github/workflows/hifis-push.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,12 @@ jobs:
runs-on: ubuntu-latest
if: ${{ github.repository_owner == 'nest' }}
steps:
- name: Harden Runner
uses: step-security/harden-runner@cba0d00b1fc9a034e1e642ea0f1103c282990604 # v2.5.0
with:
egress-policy: audit
disable-telemetry: true

- name: sycnmaster
uses: wei/git-sync@55c6b63b4f21607da0e9877ca9b4d11a29fc6d83
with:
Expand Down
6 changes: 6 additions & 0 deletions .github/workflows/jsc-push.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,12 @@ jobs:
runs-on: ubuntu-latest
if: ${{ github.repository_owner == 'nest' }}
steps:
- name: Harden Runner
uses: step-security/harden-runner@cba0d00b1fc9a034e1e642ea0f1103c282990604 # v2.5.0
with:
egress-policy: audit
disable-telemetry: true

- name: sycnmaster
uses: wei/git-sync@55c6b63b4f21607da0e9877ca9b4d11a29fc6d83
with:
Expand Down
Loading

0 comments on commit 3b762d4

Please sign in to comment.