Skip to content

Commit ee92e84

Browse files
authored
Merge pull request #10 from jedsalazar/pr/jed/github-token-lp
Add hardened runner
2 parents c7bc05c + 0b4b846 commit ee92e84

File tree

2 files changed

+19
-1
lines changed

2 files changed

+19
-1
lines changed

.github/workflows/build.yml

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,9 @@ env:
1010
GHCR_USER: ${{ github.repository_owner }}
1111
GHCR_PASS: ${{ github.token }}
1212

13+
permissions:
14+
contents: read
15+
1316
jobs:
1417
build:
1518
runs-on: ubuntu-latest
@@ -18,8 +21,13 @@ jobs:
1821
packages: write
1922
id-token: write # needed for GitHub OIDC Token
2023
steps:
24+
- name: Harden Runner
25+
uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
26+
with:
27+
egress-policy: audit
28+
2129
- name: Build, sign, inspect an image using wolfi-act
22-
uses: wolfi-dev/wolfi-act@main
30+
uses: wolfi-dev/wolfi-act@c7bc05c8af23bca710b267e0db3b39c939eb7b02 # main
2331
with:
2432
packages: curl,apko,cosign,crane,grype,trivy
2533
command: |

.github/workflows/ci.yml

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,11 @@ jobs:
1212
runs-on: ubuntu-latest
1313

1414
steps:
15+
- name: Harden Runner
16+
uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
17+
with:
18+
egress-policy: audit
19+
1520
- uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
1621

1722
- name: Build, sign, inspect an image using wolfi-act
@@ -49,6 +54,11 @@ jobs:
4954
runs-on: ubuntu-latest
5055

5156
steps:
57+
- name: Harden Runner
58+
uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
59+
with:
60+
egress-policy: audit
61+
5262
- uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
5363

5464
- name: Build, sign, inspect an image using wolfi-act

0 commit comments

Comments
 (0)