3131 docs : ${{ steps.filter.outputs.docs }}
3232 helm : ${{ steps.filter.outputs.helm }}
3333 steps :
34+ - name : Harden the runner (Audit all outbound calls)
35+ uses : step-security/harden-runner@v2
36+ with :
37+ egress-policy : audit
38+
3439 - name : Checkout repo
3540 uses : actions/checkout@v4
3641 - name : Check changed files
6469 runs-on : ubuntu-22.04
6570 timeout-minutes : 5
6671 steps :
72+ - name : Harden the runner (Audit all outbound calls)
73+ uses : step-security/harden-runner@v2
74+ with :
75+ egress-policy : audit
76+
6777 - uses : actions/checkout@v4
6878 - uses : actions/setup-node@v4
6979 with :
8292 needs : changes
8393 if : needs.changes.outputs.docs == 'true'
8494 steps :
95+ - name : Harden the runner (Audit all outbound calls)
96+ uses : step-security/harden-runner@v2
97+ with :
98+ egress-policy : audit
99+
85100 - uses : actions/checkout@v4
86101 - uses : actions/setup-node@v4
87102 with :
@@ -100,6 +115,11 @@ jobs:
100115 needs : changes
101116 if : needs.changes.outputs.helm == 'true'
102117 steps :
118+ - name : Harden the runner (Audit all outbound calls)
119+ uses : step-security/harden-runner@v2
120+ with :
121+ egress-policy : audit
122+
103123 - uses : actions/checkout@v4
104124 - uses : azure/setup-helm@v4
105125 with :
@@ -114,6 +134,11 @@ jobs:
114134 needs : changes
115135 if : needs.changes.outputs.code == 'true'
116136 steps :
137+ - name : Harden the runner (Audit all outbound calls)
138+ uses : step-security/harden-runner@v2
139+ with :
140+ egress-policy : audit
141+
117142 - uses : actions/checkout@v4
118143 - uses : actions/setup-node@v4
119144 with :
@@ -131,6 +156,11 @@ jobs:
131156 needs : changes
132157 if : needs.changes.outputs.ci == 'true'
133158 steps :
159+ - name : Harden the runner (Audit all outbound calls)
160+ uses : step-security/harden-runner@v2
161+ with :
162+ egress-policy : audit
163+
134164 - name : Checkout repo
135165 uses : actions/checkout@v4
136166 - name : Check workflow files
@@ -146,6 +176,11 @@ jobs:
146176 needs : changes
147177 if : needs.changes.outputs.code == 'true'
148178 steps :
179+ - name : Harden the runner (Audit all outbound calls)
180+ uses : step-security/harden-runner@v2
181+ with :
182+ egress-policy : audit
183+
149184 - uses : actions/checkout@v4
150185 - uses : actions/setup-node@v4
151186 with :
@@ -169,6 +204,11 @@ jobs:
169204 CODECOV_TOKEN : ${{ secrets.CODECOV_TOKEN }}
170205 DISABLE_V8_COMPILE_CACHE : 1
171206 steps :
207+ - name : Harden the runner (Audit all outbound calls)
208+ uses : step-security/harden-runner@v2
209+ with :
210+ egress-policy : audit
211+
172212 - uses : actions/checkout@v4
173213 with :
174214 submodules : true
@@ -231,6 +271,11 @@ jobs:
231271 needs : [changes, build]
232272 if : needs.changes.outputs.code == 'true' || needs.changes.outputs.deps == 'true'
233273 steps :
274+ - name : Harden the runner (Audit all outbound calls)
275+ uses : step-security/harden-runner@v2
276+ with :
277+ egress-policy : audit
278+
234279 - uses : actions/checkout@v4
235280 - run : sudo apt update && sudo apt install -y libkrb5-dev
236281 - uses : actions/setup-node@v4
@@ -265,6 +310,11 @@ jobs:
265310 needs : [changes, build]
266311 if : needs.changes.outputs.code == 'true' || needs.changes.outputs.deps == 'true'
267312 steps :
313+ - name : Harden the runner (Audit all outbound calls)
314+ uses : step-security/harden-runner@v2
315+ with :
316+ egress-policy : audit
317+
268318 - uses : actions/checkout@v4
269319 - run : sudo apt update && sudo apt install -y libkrb5-dev
270320 - uses : actions/setup-node@v4
0 commit comments