File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change 2424 name : Action lint
2525 runs-on : ubuntu-latest
2626 steps :
27- - uses : step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16 .0
27+ - uses : step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17 .0
2828 with :
2929 egress-policy : block
3030 allowed-endpoints : >
4848 echo "files=${yamls[*]}" >> "${GITHUB_OUTPUT}"
4949
5050 - name : Action lint
51- uses : step-security/action-actionlint@d364e70a116a460ed220d67b1ca2f2579c48a40a # v1.69.1
51+ uses : step-security/action-actionlint@c3aa382d371c6b05513ae5907d4f77713e21813c # v1.72.0
5252 env :
5353 SHELLCHECK_OPTS : " --exclude=SC2129 --severity=error"
5454 with :
Original file line number Diff line number Diff line change @@ -22,15 +22,15 @@ jobs:
2222
2323 steps :
2424 - name : ' Github Actions Runner'
25- uses : step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
25+ uses : step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
2626 with :
2727 egress-policy : audit
2828
2929 - name : ' Checkout default branch to $GITHUB_WORKSPACE dir'
3030 uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
3131
3232 - name : ' Setup gitsign'
33- uses : chainguard-dev/actions/setup-gitsign@f45211d3e8f9d2676c6b8cdd6a765435e06c819d # v1.6.13
33+ uses : chainguard-dev/actions/setup-gitsign@de68b87302e6266db5fb5220246f8aa46fe94b67 # v1.6.14
3434
3535 - name : Authenticate to Google Cloud
3636 id : auth
7373 identity : edu
7474
7575 - name : Create a PR
76- uses : peter-evans/create-pull-request@c0f553fe549906ede9cf27b5156039d195d2ece0 # v8.1.0
76+ uses : peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1
7777 id : cpr
7878 with :
7979 token : ${{ steps.octo-sts.outputs.token }}
Original file line number Diff line number Diff line change 3434
3535 steps :
3636 - name : ' Github Actions Runner'
37- uses : step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
37+ uses : step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
3838 with :
3939 egress-policy : audit
4040
Original file line number Diff line number Diff line change 2626
2727 steps :
2828 - name : ' Github Actions Runner'
29- uses : step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
29+ uses : step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
3030 with :
3131 egress-policy : audit
3232
Original file line number Diff line number Diff line change 2323
2424 steps :
2525 - name : ' Github Actions Runner'
26- uses : step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
26+ uses : step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
2727 with :
2828 egress-policy : audit
2929
Original file line number Diff line number Diff line change 3737
3838 steps :
3939 - name : Harden Runner
40- uses : step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
40+ uses : step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
4141 with :
4242 egress-policy : block
4343 allowed-endpoints : >
Original file line number Diff line number Diff line change 2121
2222 steps :
2323 - name : Harden the runner (Audit all outbound calls)
24- uses : step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
24+ uses : step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
2525 with :
2626 egress-policy : audit
2727
Original file line number Diff line number Diff line change 3333
3434 steps :
3535 - name : Harden the runner
36- uses : step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
36+ uses : step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
3737 with :
3838 egress-policy : block
3939 allowed-endpoints : >
7474 python-version : ' 3.10'
7575
7676 - name : Cache Python dependencies
77- uses : actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
77+ uses : actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
7878 with :
7979 path : ~/.cache/pip
8080 key : ${{ runner.os }}-pip-${{ hashFiles('**/requirements.txt') }}
Original file line number Diff line number Diff line change 3737
3838 steps :
3939 - name : Harden the runner
40- uses : step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
40+ uses : step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
4141 with :
4242 egress-policy : block
4343 allowed-endpoints : >
@@ -238,7 +238,7 @@ jobs:
238238 cosign sign --yes "ghcr.io/$REPO_OWNER/ai-docs@$DIGEST"
239239
240240 - name : Upload artifacts
241- uses : actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
241+ uses : actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
242242 with :
243243 name : chainguard-ai-docs
244244 path : |
Original file line number Diff line number Diff line change 2626
2727 steps :
2828 - name : Harden Runner
29- uses : step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
29+ uses : step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
3030 with :
3131 egress-policy : audit
3232
You can’t perform that action at this time.
0 commit comments