File tree 4 files changed +37
-12
lines changed 4 files changed +37
-12
lines changed Original file line number Diff line number Diff line change @@ -17,14 +17,19 @@ jobs:
17
17
- " v28.0.1" # 2025-02 --> EOL ?
18
18
fail-fast : false
19
19
steps :
20
- - uses : actions/checkout@v4
20
+ - name : Harden the runner (Audit all outbound calls)
21
+ uses : step-security/harden-runner@4d991eb9b905ef189e4c376166672c3f2f230481 # v2.11.0
22
+ with :
23
+ egress-policy : audit
24
+
25
+ - uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
21
26
- name : Set up JDK
22
- uses : actions/setup-java@v4
27
+ uses : actions/setup-java@3a4f6e1af504cf6a31855fa899c6aa5355ba6c12 # v4.7.0
23
28
with :
24
29
java-version : 17
25
30
distribution : temurin
26
31
- name : Set up Docker
27
- uses : docker/setup-docker-action@v4
32
+ uses : docker/setup-docker-action@b60f85385d03ac8acfca6d9996982511d8620a19 # v4.3.0
28
33
with :
29
34
version : ${{ matrix.docker-version }}
30
35
- name : Build with Gradle
Original file line number Diff line number Diff line change @@ -20,11 +20,16 @@ jobs:
20
20
GITHUB_TOKEN : " ${{ secrets.GITHUB_TOKEN }}"
21
21
PRERELEASE : " ${{ github.event.inputs.prerelease }}"
22
22
steps :
23
- - uses : actions/checkout@v4
23
+ - name : Harden the runner (Audit all outbound calls)
24
+ uses : step-security/harden-runner@4d991eb9b905ef189e4c376166672c3f2f230481 # v2.11.0
25
+ with :
26
+ egress-policy : audit
27
+
28
+ - uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
24
29
with :
25
30
fetch-depth : 0
26
31
- name : Set up JDK
27
- uses : actions/setup-java@v4
32
+ uses : actions/setup-java@3a4f6e1af504cf6a31855fa899c6aa5355ba6c12 # v4.7.0
28
33
with :
29
34
java-version : 17
30
35
distribution : temurin
Original file line number Diff line number Diff line change @@ -19,14 +19,19 @@ jobs:
19
19
- " v28.0.1" # 2025-02 --> EOL ?
20
20
fail-fast : false
21
21
steps :
22
- - uses : actions/checkout@v4
22
+ - name : Harden the runner (Audit all outbound calls)
23
+ uses : step-security/harden-runner@4d991eb9b905ef189e4c376166672c3f2f230481 # v2.11.0
24
+ with :
25
+ egress-policy : audit
26
+
27
+ - uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
23
28
- name : Set up JDK
24
- uses : actions/setup-java@v4
29
+ uses : actions/setup-java@3a4f6e1af504cf6a31855fa899c6aa5355ba6c12 # v4.7.0
25
30
with :
26
31
java-version : 17
27
32
distribution : temurin
28
33
- name : Set up Docker
29
- uses : docker/setup-docker-action@v4
34
+ uses : docker/setup-docker-action@b60f85385d03ac8acfca6d9996982511d8620a19 # v4.3.0
30
35
with :
31
36
version : ${{ matrix.docker-version }}
32
37
- name : Build with Gradle
@@ -38,11 +43,16 @@ jobs:
38
43
GITHUB_USER : " gocd-contrib"
39
44
GITHUB_TOKEN : " ${{ secrets.GITHUB_TOKEN }}"
40
45
steps :
41
- - uses : actions/checkout@v4
46
+ - name : Harden the runner (Audit all outbound calls)
47
+ uses : step-security/harden-runner@4d991eb9b905ef189e4c376166672c3f2f230481 # v2.11.0
48
+ with :
49
+ egress-policy : audit
50
+
51
+ - uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
42
52
with :
43
53
fetch-depth : 0
44
54
- name : Set up JDK
45
- uses : actions/setup-java@v4
55
+ uses : actions/setup-java@3a4f6e1af504cf6a31855fa899c6aa5355ba6c12 # v4.7.0
46
56
with :
47
57
java-version : 17
48
58
distribution : temurin
Original file line number Diff line number Diff line change 10
10
runs-on : ubuntu-latest
11
11
12
12
steps :
13
- - uses : actions/checkout@v4
13
+ - name : Harden the runner (Audit all outbound calls)
14
+ uses : step-security/harden-runner@4d991eb9b905ef189e4c376166672c3f2f230481 # v2.11.0
15
+ with :
16
+ egress-policy : audit
17
+
18
+ - uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
14
19
15
20
- name : Update Gradle Wrapper
16
- uses : gradle-update/update-gradle-wrapper-action@v2
21
+ uses : gradle-update/update-gradle-wrapper-action@512b1875f3b6270828abfe77b247d5895a2da1e5 # v2.1.0
17
22
with :
18
23
labels : dependencies
You can’t perform that action at this time.
0 commit comments