Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 8 additions & 8 deletions .github/workflows/ci-verify.yml
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden the runner (block all outbound calls except the allowlist)
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: block
# This job only checks out the repo and runs local node --test files;
Expand Down Expand Up @@ -71,7 +71,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden the runner (block all outbound calls except the allowlist)
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: block
# checkout + npm ci, plus the full suite's own live calls: job-link-checker's
Expand Down Expand Up @@ -157,7 +157,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden the runner (block all outbound calls except the allowlist)
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: block
# checkout + npm ci + npm run build; observed on run 32512881196
Expand Down Expand Up @@ -243,7 +243,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden the runner (block all outbound calls except the allowlist)
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: block
# checkout + npm ci + npm run build (apps/website, apps/docs); observed
Expand Down Expand Up @@ -325,7 +325,7 @@ jobs:
runs-on: windows-latest
steps:
- name: Harden the runner (audit Electron and Chromium downloads)
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: audit
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
Expand Down Expand Up @@ -428,7 +428,7 @@ jobs:
CAREERRAT_LIVE_BROWSER: "1"
steps:
- name: Harden the runner (audit Chromium and system dependency downloads)
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: audit
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
Expand Down Expand Up @@ -533,7 +533,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden the runner (block all outbound calls except the allowlist)
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: block
# Qlty pulls its own binary plus the Python/Go/Node toolchains its
Expand Down Expand Up @@ -592,7 +592,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden the runner (block all outbound calls except the allowlist)
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: block
# checkout + npm ci + npx knip; observed on run 32512881196 (Stable
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ jobs:
language: [javascript-typescript]
steps:
- name: Harden the runner (block all outbound calls except the allowlist)
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: block
# checkout, CodeQL bundle download (release-assets.githubusercontent.com
Expand All @@ -49,10 +49,10 @@ jobs:
with:
persist-credentials: false
- name: Initialize CodeQL
uses: github/codeql-action/init@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd # v4.37.7
uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0
with:
languages: ${{ matrix.language }}
- name: Perform CodeQL analysis
uses: github/codeql-action/analyze@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd # v4.37.7
uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0
with:
category: "/language:${{ matrix.language }}"
10 changes: 5 additions & 5 deletions .github/workflows/desktop-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,7 @@ jobs:
tag: ${{ steps.resolve.outputs.tag }}
steps:
- name: Harden the runner (block all outbound calls except the allowlist)
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: block
# This job only calls `gh api repos/.../tags` (dispatch path) and
Expand Down Expand Up @@ -124,7 +124,7 @@ jobs:
REPO: ${{ github.repository }}
steps:
- name: Harden the runner (block all outbound calls except the allowlist)
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: block
allowed-endpoints: >
Expand Down Expand Up @@ -208,7 +208,7 @@ jobs:
TAG: ${{ needs.resolve-tag.outputs.tag }}
steps:
- name: Harden the runner (audit all outbound calls)
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
# Stays on audit: this job's notarytool/stapler calls hit
# Apple/Akamai/S3 hosts (appstoreconnect.apple.com,
Expand Down Expand Up @@ -366,7 +366,7 @@ jobs:
REPO: ${{ github.repository }}
steps:
- name: Harden the runner (audit dependency, browser, and signing endpoints)
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: audit
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
Expand Down Expand Up @@ -498,7 +498,7 @@ jobs:
WINDOWS_PUBLISHED: ${{ needs.build-windows-upload.outputs.published }}
steps:
- name: Harden the runner (block all outbound calls except the allowlist)
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: block
# Release lookup/publication plus workflow dispatch and child-run
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ jobs:
REF_NAME: ${{ github.ref_name }}
steps:
- name: Harden the runner (block all outbound calls except the allowlist)
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: block
# checkout, exact-release/feed verification, dependency install, and
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/quality-ruleset-drift.yml
Original file line number Diff line number Diff line change
Expand Up @@ -57,7 +57,7 @@ jobs:
contents: read # rulesets are world-readable on a public repo; see the header note
steps:
- name: Harden the runner (block all outbound calls except the allowlist)
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: block
# checkout plus `gh api repos/.../rulesets` (both verify scripts).
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/release-assets.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ jobs:
REF_NAME: ${{ github.ref_name }}
steps:
- name: Harden the runner (block all outbound calls except the allowlist)
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: block
# checkout plus `gh release view`. Observed on run 32488752322
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/sbom.yml
Original file line number Diff line number Diff line change
Expand Up @@ -59,7 +59,7 @@ jobs:
version: ${{ steps.resolve.outputs.version }}
steps:
- name: Harden the runner (block all outbound calls except the allowlist)
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: block
# This job only calls `gh api repos/.../releases`, the same
Expand Down Expand Up @@ -127,7 +127,7 @@ jobs:
REPO: ${{ github.repository }}
steps:
- name: Harden the runner (block all outbound calls except the allowlist)
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: block
# Observed from the v0.12.0 run (StepSecurity insights, run
Expand Down Expand Up @@ -157,7 +157,7 @@ jobs:
- name: Install dependencies
run: npm ci
- name: Generate the SPDX SBOM
uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0
uses: anchore/sbom-action@3ad7283483fc7af8ff2b4ea19663c2d5ca935e26 # v0.24.2
with:
path: .
format: spdx-json
Expand Down
12 changes: 6 additions & 6 deletions .github/workflows/security-actions.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ jobs:
contents: read
steps:
- name: Harden the runner (block all outbound calls except the allowlist)
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: block
# raven-actions/actionlint installs actionlint via a Python/pip helper
Expand Down Expand Up @@ -56,7 +56,7 @@ jobs:
contents: read
steps:
- name: Harden the runner (block all outbound calls except the allowlist)
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: block
# astral-sh/setup-uv fetches uv from its GitHub release
Expand All @@ -74,11 +74,11 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
- uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
with:
# Pin the last mirror-verified release instead of racing a newly
# published `latest` before its Astral mirror asset is available.
version: "0.12.5"
version: "0.12.15"
- name: Scan workflows for Actions security anti-patterns
run: uvx zizmor==1.29.0 .github/workflows/ --min-severity medium

Expand All @@ -97,7 +97,7 @@ jobs:
GITLEAKS_LINUX_X64_SHA256: "551f6fc83ea457d62a0d98237cbad105af8d557003051f41f3e7ca7b3f2470eb"
steps:
- name: Harden the runner (block all outbound calls except the allowlist)
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: block
# checkout plus the pinned-and-hash-verified gitleaks tarball download
Expand Down Expand Up @@ -129,7 +129,7 @@ jobs:
contents: read
steps:
- name: Harden the runner (block all outbound calls except the allowlist)
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: block
# actions/dependency-review-action calls the GitHub dependency-graph
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/security-dast.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ jobs:
permissions: {}
steps:
- name: Harden the runner (audit all outbound calls)
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
# Stays on audit: the ZAP baseline scan spiders the live
# careerrat.com production site and follows whatever it links to
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/security-scorecard.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ jobs:
actions: read
steps:
- name: Harden the runner (block all outbound calls except the allowlist)
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: block
# ossf/scorecard-action's own dependencies: it checks OSS-Fuzz
Expand Down Expand Up @@ -62,6 +62,6 @@ jobs:
results_format: sarif
publish_results: true
- name: Upload SARIF results to code scanning
uses: github/codeql-action/upload-sarif@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd # v4.37.7
uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0
with:
sarif_file: results.sarif
Loading