File tree Expand file tree Collapse file tree 19 files changed +1174
-561
lines changed Expand file tree Collapse file tree 19 files changed +1174
-561
lines changed Original file line number Diff line number Diff line change @@ -38,12 +38,12 @@ jobs:
3838
3939 steps :
4040 - name : Harden Runner
41- uses : step-security/harden-runner@4d991eb9b905ef189e4c376166672c3f2f230481 # v2.11.0
41+ uses : step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
4242 with :
4343 egress-policy : audit
4444
4545 - name : Checkout repository
46- uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
46+ uses : actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
4747
4848 # Initializes the CodeQL tools for scanning.
4949 - name : Initialize CodeQL
Original file line number Diff line number Diff line change 2727 runs-on : ubuntu-latest
2828 steps :
2929 - name : Harden Runner
30- uses : step-security/harden-runner@4d991eb9b905ef189e4c376166672c3f2f230481 # v2.11.0
30+ uses : step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
3131 with :
3232 disable-sudo : false
3333 egress-policy : block
4242 registry.npmjs.org:443
4343 54.185.253.63:443
4444
45- - uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
45+ - uses : actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
4646 with :
4747 submodules : recursive
4848
@@ -53,13 +53,13 @@ jobs:
5353 yarn set version 4.9.2
5454
5555 - name : Setup Node.js environment
56- uses : actions/setup-node@1d0ff469b7ec7b3cb9d8673fde0c81c44821de2a # v4.2 .0
56+ uses : actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4 .0
5757 with :
5858 node-version : 20.x
5959 cache : yarn
6060
6161 - name : Cache node modules
62- uses : actions/cache@0c907a75c2c80ebcb7f088228285e798b750cf8f # v4.2.1
62+ uses : actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
6363 env :
6464 cache-name : cache-node-modules
6565 with :
Original file line number Diff line number Diff line change 1919 runs-on : ubuntu-latest
2020 steps :
2121 - name : Harden Runner
22- uses : step-security/harden-runner@4d991eb9b905ef189e4c376166672c3f2f230481 # v2.11.0
22+ uses : step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
2323 with :
2424 disable-sudo : true
2525 egress-policy : block
@@ -31,10 +31,10 @@ jobs:
3131 acghubeus1.actions.githubusercontent.com:443
3232
3333 - name : ' Checkout Repository'
34- uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
34+ uses : actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
3535
3636 - name : ' Dependency Review'
37- uses : actions/dependency-review-action@3b139cfc5fae8b618d3eae3675e383bb1769c019 # v4.5.0
37+ uses : actions/dependency-review-action@40c09b7dc99638e5ddb0bfd91c1673effc064d8a # v4.8.1
3838 with :
3939 base-ref : ${{ github.event.pull_request.base.sha || 'dev' }}
4040 head-ref : ${{ github.event.pull_request.head.sha || github.ref }}
Original file line number Diff line number Diff line change 88 runs-on : ubuntu-latest
99 steps :
1010 - name : Harden Runner
11- uses : step-security/harden-runner@4d991eb9b905ef189e4c376166672c3f2f230481 # v2.11.0
11+ uses : step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
1212 with :
1313 egress-policy : audit # TODO: change to 'egress-policy: block' after couple of runs
1414
Original file line number Diff line number Diff line change 3535 environment : ${{ inputs.graph_environment }}
3636 steps :
3737 - name : Harden Runner
38- uses : step-security/harden-runner@4d991eb9b905ef189e4c376166672c3f2f230481 # v2.11.0
38+ uses : step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
3939 with :
4040 egress-policy : audit
4141
@@ -44,10 +44,10 @@ jobs:
4444 run : echo ${{vars.NETWORK}} && exit 1
4545
4646 - name : Checkout code
47- uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
47+ uses : actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
4848
4949 - name : Set up Node.js
50- uses : actions/setup-node@1d0ff469b7ec7b3cb9d8673fde0c81c44821de2a # v4.2 .0
50+ uses : actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4 .0
5151 with :
5252 node-version : 20
5353
Original file line number Diff line number Diff line change 3232
3333 steps :
3434 - name : Harden Runner
35- uses : step-security/harden-runner@4d991eb9b905ef189e4c376166672c3f2f230481 # v2.11.0
35+ uses : step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
3636 with :
3737 disable-sudo : true
3838 egress-policy : block
@@ -51,12 +51,12 @@ jobs:
5151 sigstore-tuf-root.storage.googleapis.com:443
5252
5353 - name : " Checkout code"
54- uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
54+ uses : actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
5555 with :
5656 persist-credentials : false
5757
5858 - name : " Run analysis"
59- uses : ossf/scorecard-action@f49aabe0b5af0936a0987cfb85d86b75731b0186 # v2.4.1
59+ uses : ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3
6060 with :
6161 results_file : results.sarif
6262 results_format : sarif
7878 # Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
7979 # format to the repository Actions tab.
8080 - name : " Upload artifact"
81- uses : actions/upload-artifact@4cec3d8aa04e39d1a68397de0c4cd6fb9dce8ec1 # v4.6.1
81+ uses : actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
8282 with :
8383 name : SARIF file
8484 path : results.sarif
Original file line number Diff line number Diff line change 1717 version : ${{ steps.set-version.outputs.version }}
1818 steps :
1919 - name : Harden Runner
20- uses : step-security/harden-runner@4d991eb9b905ef189e4c376166672c3f2f230481 # v2.11.0
20+ uses : step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
2121 with :
2222 disable-sudo : true
2323 egress-policy : block
3333 54.185.253.63:443
3434 sentry.io:443
3535
36- - uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
36+ - uses : actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
3737 with :
3838 submodules : recursive
3939
@@ -44,13 +44,13 @@ jobs:
4444 yarn set version 4.5.1
4545
4646 - name : Setup Node.js environment
47- uses : actions/setup-node@1d0ff469b7ec7b3cb9d8673fde0c81c44821de2a # v4.2 .0
47+ uses : actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4 .0
4848 with :
4949 node-version : 20.x
5050 cache : yarn
5151
5252 - name : Cache node modules
53- uses : actions/cache@0c907a75c2c80ebcb7f088228285e798b750cf8f # v4.2.1
53+ uses : actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
5454 env :
5555 cache-name : cache-node-modules
5656 with :
7272 working-directory : web
7373
7474 - name : Create Sentry release
75- uses : getsentry/action-release@ffb64465339ef6fb868e2fc261318d78ae0ed8d9 # v1.10.5
75+ uses : getsentry/action-release@a74facf8a080ecbdf1cb355f16743530d712abb7 # v1.11.0
7676 env :
7777 SENTRY_AUTH_TOKEN : ${{ secrets.SENTRY_AUTH_TOKEN }}
7878 SENTRY_ORG : ${{ secrets.SENTRY_ORG }}
Original file line number Diff line number Diff line change @@ -19,11 +19,11 @@ jobs:
1919 runs-on : ubuntu-latest
2020 steps :
2121 - name : Harden Runner
22- uses : step-security/harden-runner@4d991eb9b905ef189e4c376166672c3f2f230481 # v2.11.0
22+ uses : step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
2323 with :
2424 egress-policy : audit
2525
26- - uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
26+ - uses : actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
2727 with :
2828 fetch-depth : 0 # Shallow clones should be disabled for a better relevancy of analysis
2929
You can’t perform that action at this time.
0 commit comments