Skip to content

Commit a8a480e

Browse files
authored
Merge pull request #81 from step-security-bot/stepsecurity_remediation_1742548730
[StepSecurity] ci: Harden GitHub Actions
2 parents 373fa87 + 0ca3a96 commit a8a480e

File tree

1 file changed

+7
-2
lines changed

1 file changed

+7
-2
lines changed

.github/workflows/update-gradle-wrapper.yml

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -10,9 +10,14 @@ jobs:
1010
runs-on: ubuntu-latest
1111

1212
steps:
13-
- uses: actions/checkout@v4
13+
- name: Harden the runner (Audit all outbound calls)
14+
uses: step-security/harden-runner@4d991eb9b905ef189e4c376166672c3f2f230481 # v2.11.0
15+
with:
16+
egress-policy: audit
17+
18+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
1419

1520
- name: Update Gradle Wrapper
16-
uses: gradle-update/update-gradle-wrapper-action@v2
21+
uses: gradle-update/update-gradle-wrapper-action@512b1875f3b6270828abfe77b247d5895a2da1e5 # v2.1.0
1722
with:
1823
labels: dependencies

0 commit comments

Comments
 (0)