|
17 | 17 | platform: [ 'x86_64-unknown-linux-gnu', 'aarch64-unknown-linux-gnu' ]
|
18 | 18 | steps:
|
19 | 19 | - name: Harden Runner
|
20 |
| - uses: step-security/harden-runner@1b05615854632b887b69ae1be8cbefe72d3ae423 |
| 20 | + uses: step-security/harden-runner@eb238b55efaa70779f274895e782ed17c84f2895 |
21 | 21 | with:
|
22 | 22 | egress-policy: block
|
23 | 23 | allowed-endpoints: >
|
|
68 | 68 | python-version: ['3.8', '3.9', '3.10', '3.11', '3.12']
|
69 | 69 | steps:
|
70 | 70 | - name: Harden Runner
|
71 |
| - uses: step-security/harden-runner@1b05615854632b887b69ae1be8cbefe72d3ae423 |
| 71 | + uses: step-security/harden-runner@eb238b55efaa70779f274895e782ed17c84f2895 |
72 | 72 | with:
|
73 | 73 | egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
|
74 | 74 |
|
|
98 | 98 | target: ['universal2', 'x86_64-apple-darwin']
|
99 | 99 | steps:
|
100 | 100 | - name: Harden Runner
|
101 |
| - uses: step-security/harden-runner@1b05615854632b887b69ae1be8cbefe72d3ae423 |
| 101 | + uses: step-security/harden-runner@eb238b55efaa70779f274895e782ed17c84f2895 |
102 | 102 | with:
|
103 | 103 | egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
|
104 | 104 |
|
@@ -129,7 +129,7 @@ jobs:
|
129 | 129 | contents: write # To add assets to a release.
|
130 | 130 | steps:
|
131 | 131 | - name: Harden Runner
|
132 |
| - uses: step-security/harden-runner@1b05615854632b887b69ae1be8cbefe72d3ae423 # v2.1.0 |
| 132 | + uses: step-security/harden-runner@eb238b55efaa70779f274895e782ed17c84f2895 # v2.1.0 |
133 | 133 | with:
|
134 | 134 | disable-sudo: true
|
135 | 135 | egress-policy: block
|
@@ -172,7 +172,7 @@ jobs:
|
172 | 172 | id-token: write # IMPORTANT: this permission is mandatory for trusted publishing
|
173 | 173 | steps:
|
174 | 174 | - name: Harden Runner
|
175 |
| - uses: step-security/harden-runner@1b05615854632b887b69ae1be8cbefe72d3ae423 |
| 175 | + uses: step-security/harden-runner@eb238b55efaa70779f274895e782ed17c84f2895 |
176 | 176 | with:
|
177 | 177 | egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
|
178 | 178 |
|
|
0 commit comments