Skip to content

Commit 8819abc

Browse files
authored
chore: add Harden Runner to all workflows (#125)
1 parent 0ad494c commit 8819abc

File tree

6 files changed

+36
-0
lines changed

6 files changed

+36
-0
lines changed

.github/workflows/bump-version.yaml

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,10 @@ jobs:
1818
issues: write
1919
pull-requests: write
2020
steps:
21+
- name: Harden Runner
22+
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
23+
with:
24+
egress-policy: audit
2125
- uses: mheap/github-action-required-labels@8afbe8ae6ab7647d0c9f0cfa7c2f939650d22509 # v5.5
2226
if: github.actor != 'dependabot[bot]'
2327
with:
@@ -33,6 +37,10 @@ jobs:
3337
pull-requests: write
3438
contents: write
3539
steps:
40+
- name: Harden Runner
41+
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
42+
with:
43+
egress-policy: audit
3644
- name: Install Speakeasy
3745
uses: mheap/setup-go-cli@fa9b01cdd4115eac636164f0de43bf7d51c82697 # v1.2.2
3846
with:

.github/workflows/codeql.yaml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -34,6 +34,10 @@ jobs:
3434
matrix:
3535
language: [ 'go' ]
3636
steps:
37+
- name: Harden Runner
38+
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
39+
with:
40+
egress-policy: audit
3741
- name: Checkout repository
3842
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
3943
- name: Install Go

.github/workflows/generate_on_pr.yaml

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -20,6 +20,10 @@ jobs:
2020
outputs:
2121
result: ${{ steps.decision.outputs.result }}
2222
steps:
23+
- name: Harden Runner
24+
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
25+
with:
26+
egress-policy: audit
2327
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
2428
with:
2529
ref: ${{ github.event.pull_request.head.ref }}
@@ -41,6 +45,10 @@ jobs:
4145
- ubuntu-latest
4246
if: needs.should-generate.outputs.result == 'true'
4347
steps:
48+
- name: Harden Runner
49+
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
50+
with:
51+
egress-policy: audit
4452
- name: Install Speakeasy
4553
uses: mheap/setup-go-cli@fa9b01cdd4115eac636164f0de43bf7d51c82697 # v1.2.2
4654
with:

.github/workflows/konnect-cleanup.yaml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -27,6 +27,10 @@ jobs:
2727
- konnect-api-url: https://us.api.konghq.tech
2828
- konnect-api-url: https://eu.api.konghq.tech
2929
steps:
30+
- name: Harden Runner
31+
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
32+
with:
33+
egress-policy: audit
3034
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
3135

3236
- uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5

.github/workflows/release.yaml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,10 @@ jobs:
1919
permissions:
2020
contents: write
2121
steps:
22+
- name: Harden Runner
23+
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
24+
with:
25+
egress-policy: audit
2226
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
2327
with:
2428
# Allow goreleaser to access older tag information.

.github/workflows/tests.yaml

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -25,6 +25,10 @@ jobs:
2525
unit-tests:
2626
runs-on: ubuntu-latest
2727
steps:
28+
- name: Harden Runner
29+
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
30+
with:
31+
egress-policy: audit
2832
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
2933

3034
- uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5
@@ -43,6 +47,10 @@ jobs:
4347
- konnect-api-url: https://us.api.konghq.tech
4448
- konnect-api-url: https://eu.api.konghq.tech
4549
steps:
50+
- name: Harden Runner
51+
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
52+
with:
53+
egress-policy: audit
4654
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
4755

4856
- uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5

0 commit comments

Comments
 (0)