File tree Expand file tree Collapse file tree 1 file changed +11
-3
lines changed Expand file tree Collapse file tree 1 file changed +11
-3
lines changed Original file line number Diff line number Diff line change 11
11
# Run weekly on day 0 at 00:00 UTC
12
12
- cron : " 0 0 * * 0"
13
13
14
+ permissions :
15
+ contents : read
16
+
14
17
jobs :
15
18
update-dependencies :
16
19
permissions :
20
23
name : Update dependencies
21
24
runs-on : ubuntu-latest
22
25
steps :
23
- - uses : actions/checkout@v3
24
- - uses : actions/setup-python@v4
26
+ - name : Harden Runner
27
+ uses : step-security/harden-runner@dd2c410b088af7c0dc8046f3ac9a8f4148492a95
28
+ with :
29
+ egress-policy : audit # TODO: change to 'egress-policy: block' after couple of runs
30
+
31
+ - uses : actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b
32
+ - uses : actions/setup-python@b55428b1882923874294fa556849718a1d7f2ca5
25
33
with :
26
34
python-version : " 3.10"
27
35
- name : Install test dependencies
51
59
run : pip-compile --upgrade --output-file=requirements/deploy.txt requirements/deploy.in
52
60
53
61
- name : Create Pull Request
54
- uses : peter-evans/create-pull-request@v4
62
+ uses : peter-evans/create-pull-request@171dd555b9ab6b18fa02519fdfacbb8bf671e1b4
55
63
with :
56
64
add-paths : |
57
65
requirements/*.txt
You can’t perform that action at this time.
0 commit comments