Skip to content

Commit 0e40b83

Browse files
committed
ci: block network access when not required
1 parent 09677d0 commit 0e40b83

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

.github/workflows/wc-sanitize-image-name.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -36,8 +36,8 @@ jobs:
3636
steps:
3737
- uses: step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
3838
with:
39-
disable-sudo: true
40-
egress-policy: audit
39+
disable-sudo-and-containers: true
40+
egress-policy: block
4141
- name: Sanitize image name
4242
id: sanitize-image-name
4343
env:

0 commit comments

Comments
 (0)