From 32b97a380b50532912acefa05bd85f6dce9cf8c3 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 30 Sep 2022 00:00:38 +0000 Subject: [PATCH] Bump step-security/harden-runner from 1.4.5 to 1.5.0 Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 1.4.5 to 1.5.0. - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](https://github.com/step-security/harden-runner/compare/dd2c410b088af7c0dc8046f3ac9a8f4148492a95...2e205a28d0e1da00c5f53b161f4067b052c61f34) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] --- .github/workflows/assign-to-project.yml | 2 +- .github/workflows/auto-assign-pr.yml | 2 +- .github/workflows/ci-build.yml | 2 +- .github/workflows/codeql-scan.yml | 2 +- .github/workflows/docker-linter.yml | 2 +- .github/workflows/mark-stale.yml | 2 +- .github/workflows/pr-labeler.yml | 2 +- .github/workflows/release-build.yml | 4 ++-- 8 files changed, 9 insertions(+), 9 deletions(-) diff --git a/.github/workflows/assign-to-project.yml b/.github/workflows/assign-to-project.yml index df19bb1..1b7a4bc 100644 --- a/.github/workflows/assign-to-project.yml +++ b/.github/workflows/assign-to-project.yml @@ -20,7 +20,7 @@ jobs: steps: - name: Harden Runner - uses: step-security/harden-runner@dd2c410b088af7c0dc8046f3ac9a8f4148492a95 + uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 with: egress-policy: block allowed-endpoints: > diff --git a/.github/workflows/auto-assign-pr.yml b/.github/workflows/auto-assign-pr.yml index 8723a8b..2523408 100644 --- a/.github/workflows/auto-assign-pr.yml +++ b/.github/workflows/auto-assign-pr.yml @@ -13,7 +13,7 @@ jobs: steps: - name: Harden Runner - uses: step-security/harden-runner@dd2c410b088af7c0dc8046f3ac9a8f4148492a95 + uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 with: egress-policy: block allowed-endpoints: > diff --git a/.github/workflows/ci-build.yml b/.github/workflows/ci-build.yml index bf568fe..44cb424 100644 --- a/.github/workflows/ci-build.yml +++ b/.github/workflows/ci-build.yml @@ -21,7 +21,7 @@ jobs: steps: - name: Harden Runner - uses: step-security/harden-runner@dd2c410b088af7c0dc8046f3ac9a8f4148492a95 + uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 with: egress-policy: block allowed-endpoints: > diff --git a/.github/workflows/codeql-scan.yml b/.github/workflows/codeql-scan.yml index 1644a6a..809e4ee 100644 --- a/.github/workflows/codeql-scan.yml +++ b/.github/workflows/codeql-scan.yml @@ -37,7 +37,7 @@ jobs: steps: - name: Harden Runner - uses: step-security/harden-runner@dd2c410b088af7c0dc8046f3ac9a8f4148492a95 + uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 with: egress-policy: block allowed-endpoints: > diff --git a/.github/workflows/docker-linter.yml b/.github/workflows/docker-linter.yml index f6dbff3..efe5582 100644 --- a/.github/workflows/docker-linter.yml +++ b/.github/workflows/docker-linter.yml @@ -29,7 +29,7 @@ jobs: steps: - name: Harden Runner - uses: step-security/harden-runner@dd2c410b088af7c0dc8046f3ac9a8f4148492a95 + uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 with: egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs diff --git a/.github/workflows/mark-stale.yml b/.github/workflows/mark-stale.yml index d2db4ed..9220cad 100644 --- a/.github/workflows/mark-stale.yml +++ b/.github/workflows/mark-stale.yml @@ -17,7 +17,7 @@ jobs: steps: - name: Harden Runner - uses: step-security/harden-runner@dd2c410b088af7c0dc8046f3ac9a8f4148492a95 + uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 with: egress-policy: block allowed-endpoints: > diff --git a/.github/workflows/pr-labeler.yml b/.github/workflows/pr-labeler.yml index f146da1..f2ee74e 100644 --- a/.github/workflows/pr-labeler.yml +++ b/.github/workflows/pr-labeler.yml @@ -19,7 +19,7 @@ jobs: steps: - name: Harden Runner - uses: step-security/harden-runner@dd2c410b088af7c0dc8046f3ac9a8f4148492a95 + uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 with: egress-policy: block allowed-endpoints: > diff --git a/.github/workflows/release-build.yml b/.github/workflows/release-build.yml index 88d1124..482d15a 100644 --- a/.github/workflows/release-build.yml +++ b/.github/workflows/release-build.yml @@ -21,7 +21,7 @@ jobs: steps: - name: Harden Runner - uses: step-security/harden-runner@dd2c410b088af7c0dc8046f3ac9a8f4148492a95 + uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 with: egress-policy: block allowed-endpoints: > @@ -62,7 +62,7 @@ jobs: steps: - name: Harden Runner - uses: step-security/harden-runner@dd2c410b088af7c0dc8046f3ac9a8f4148492a95 + uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 with: egress-policy: block allowed-endpoints: >