Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: apply ci hardening (sgammon/guava#1) #11

Closed
wants to merge 0 commits into from

Conversation

sgammon
Copy link
Owner

@sgammon sgammon commented Mar 8, 2024

Summary

Applies reasonable CI hardening and latest updates to GHA steps.

Note

This PR is a draft, currently under test. It will ultimately be filed upstream at google/guava.

Changelog

  • chore: apply StepSecurity auditing to all ci tasks
  • chore: apply persist-credentials: false to checkout tasks
  • chore: publish dependency graph and add dependency review check
  • chore: add codeql scan job (temp)
  • chore: add actions/dependency-review-action
  • chore: update actions/checkout4.1.1

Bumps actions/checkout from 3.6.0 to 4.1.1.

Bumps actions/dependency-review-action from 2.5.1 to 4.1.3.

@sgammon sgammon self-assigned this Mar 8, 2024
@sgammon sgammon closed this Mar 8, 2024
@sgammon sgammon force-pushed the chore/ci-security branch from 19a1569 to ece47cd Compare March 8, 2024 04:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant