Skip to content

Commit 8d6e2bc

Browse files
authored
Merge pull request #29 from step-security-bot/stepsecurity_remediation_1737992331
[StepSecurity] ci: Harden GitHub Actions
2 parents ed28da4 + f840102 commit 8d6e2bc

2 files changed

Lines changed: 23 additions & 0 deletions

File tree

.github/workflows/release.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -20,6 +20,11 @@ jobs:
2020
goreleaser:
2121
runs-on: ubuntu-latest
2222
steps:
23+
- name: Harden Runner
24+
uses: step-security/harden-runner@v2
25+
with:
26+
egress-policy: audit
27+
2328
- name: Checkout
2429
uses: actions/checkout@v3
2530

.github/workflows/test.yml

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -20,13 +20,21 @@ on:
2020
concurrency:
2121
group: ${{ github.workflow }}-${{ github.ref }}
2222
cancel-in-progress: true
23+
permissions:
24+
contents: read
25+
2326
jobs:
2427
# ensure the code builds...
2528
build:
2629
name: Build
2730
runs-on: ubuntu-latest
2831
timeout-minutes: 5
2932
steps:
33+
- name: Harden Runner
34+
uses: step-security/harden-runner@v2
35+
with:
36+
egress-policy: audit
37+
3038
- uses: actions/checkout@v3
3139
- uses: actions/setup-go@v3
3240
with:
@@ -42,6 +50,11 @@ jobs:
4250
generate:
4351
runs-on: ubuntu-latest
4452
steps:
53+
- name: Harden Runner
54+
uses: step-security/harden-runner@v2
55+
with:
56+
egress-policy: audit
57+
4558
- uses: actions/checkout@v3
4659
- uses: actions/setup-go@v3
4760
with:
@@ -71,6 +84,11 @@ jobs:
7184
- "1.1.*"
7285
- "1.2.*"
7386
steps:
87+
- name: Harden Runner
88+
uses: step-security/harden-runner@v2
89+
with:
90+
egress-policy: audit
91+
7492
- uses: actions/checkout@v3
7593
- uses: actions/setup-go@v3
7694
with:

0 commit comments

Comments
 (0)