Skip to content

Commit 0e0dc58

Browse files
[StepSecurity] ci: Harden GitHub Actions (#114)
Signed-off-by: StepSecurity Bot <[email protected]>
1 parent 4429ccd commit 0e0dc58

File tree

1 file changed

+10
-2
lines changed

1 file changed

+10
-2
lines changed

.github/workflows/pr.yml

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,13 +6,21 @@ on:
66
pull_request:
77
branches: [main]
88

9+
permissions:
10+
contents: read
11+
912
jobs:
1013
build:
1114
runs-on: ubuntu-latest
1215
steps:
13-
- uses: actions/checkout@v4
16+
- name: Harden Runner
17+
uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1
18+
with:
19+
egress-policy: audit
20+
21+
- uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
1422
- name: Setup Node.js
15-
uses: actions/setup-node@v4
23+
uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4
1624
with:
1725
node-version-file: '.nvmrc'
1826
- name: Install dependencies

0 commit comments

Comments
 (0)