Просмотр исходного кода

chore(deps): bump step-security/harden-runner from 2.16.1 to 2.17.0 (#6217)

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
dependabot[bot] 1 месяц назад
Родитель
Сommit
98e026dec4

+ 4 - 4
.github/workflows/ci.yml

@@ -23,7 +23,7 @@ jobs:
     outputs:
     outputs:
       noop: ${{ steps.noop.outputs.should_skip }}
       noop: ${{ steps.noop.outputs.should_skip }}
     steps:
     steps:
-      - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+      - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
         with:
         with:
           egress-policy: audit
           egress-policy: audit
       - name: Detect No-op Changes
       - name: Detect No-op Changes
@@ -43,7 +43,7 @@ jobs:
     if: needs.detect-noop.outputs.noop != 'true' && github.ref != 'refs/heads/main'
     if: needs.detect-noop.outputs.noop != 'true' && github.ref != 'refs/heads/main'
 
 
     steps:
     steps:
-      - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+      - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
         with:
         with:
           egress-policy: audit
           egress-policy: audit
       - name: Checkout
       - name: Checkout
@@ -61,7 +61,7 @@ jobs:
       contents: read
       contents: read
 
 
     steps:
     steps:
-      - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+      - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
         with:
         with:
           egress-policy: audit
           egress-policy: audit
       - name: Checkout
       - name: Checkout
@@ -98,7 +98,7 @@ jobs:
       contents: read
       contents: read
 
 
     steps:
     steps:
-      - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+      - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
         with:
         with:
           egress-policy: audit
           egress-policy: audit
       - name: Checkout
       - name: Checkout

+ 1 - 1
.github/workflows/codeql.yml

@@ -26,7 +26,7 @@ jobs:
           - language: actions
           - language: actions
             build-mode: none
             build-mode: none
     steps:
     steps:
-    - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+    - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
       with:
       with:
         egress-policy: audit
         egress-policy: audit
     - name: Checkout repository
     - name: Checkout repository

+ 1 - 1
.github/workflows/crds.yml

@@ -18,7 +18,7 @@ jobs:
   crd-tests:
   crd-tests:
     runs-on: ubuntu-latest
     runs-on: ubuntu-latest
     steps:
     steps:
-      - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+      - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
         with:
         with:
           egress-policy: audit
           egress-policy: audit
       - name: Checkout
       - name: Checkout

+ 1 - 1
.github/workflows/dependabot-approve.yml

@@ -12,7 +12,7 @@ jobs:
     # PRs but also ensures that it only does work for Dependabot PRs.
     # PRs but also ensures that it only does work for Dependabot PRs.
     if: github.actor == 'dependabot[bot]' && github.event.pull_request.user.login == 'dependabot[bot]'
     if: github.actor == 'dependabot[bot]' && github.event.pull_request.user.login == 'dependabot[bot]'
     steps:
     steps:
-      - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+      - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
         with:
         with:
           egress-policy: audit
           egress-policy: audit
       - uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1
       - uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1

+ 1 - 1
.github/workflows/dependency-review.yml

@@ -17,7 +17,7 @@ jobs:
     runs-on: ubuntu-latest
     runs-on: ubuntu-latest
     steps:
     steps:
       - name: Harden the runner (Audit all outbound calls)
       - name: Harden the runner (Audit all outbound calls)
-        uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+        uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
         with:
         with:
           egress-policy: audit
           egress-policy: audit
 
 

+ 1 - 1
.github/workflows/dlc.yml

@@ -16,7 +16,7 @@ jobs:
   fossa-scan:
   fossa-scan:
     runs-on: ubuntu-latest
     runs-on: ubuntu-latest
     steps:
     steps:
-      - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+      - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
         if: ${{ env.HAS_FOSSA_KEY == 'true' }}
         if: ${{ env.HAS_FOSSA_KEY == 'true' }}
         with:
         with:
           egress-policy: audit
           egress-policy: audit

+ 1 - 1
.github/workflows/docs.yml

@@ -14,7 +14,7 @@ jobs:
     permissions:
     permissions:
       contents: write #needed to publish documentation
       contents: write #needed to publish documentation
     steps:
     steps:
-      - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+      - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
         with:
         with:
           egress-policy: audit
           egress-policy: audit
       - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
       - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

+ 4 - 4
.github/workflows/e2e-managed.yml

@@ -28,7 +28,7 @@ jobs:
     outputs:
     outputs:
       check_run_id: ${{ steps.create_check.outputs.check_run_id }}
       check_run_id: ${{ steps.create_check.outputs.check_run_id }}
     steps:
     steps:
-      - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+      - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
         with:
         with:
           egress-policy: audit
           egress-policy: audit
 
 
@@ -82,7 +82,7 @@ jobs:
       TF_VAR_AWS_SA_NAME: ${{ secrets.AWS_SA_NAME }}
       TF_VAR_AWS_SA_NAME: ${{ secrets.AWS_SA_NAME }}
       TF_VAR_AWS_SA_NAMESPACE: ${{ secrets.AWS_SA_NAMESPACE }}
       TF_VAR_AWS_SA_NAMESPACE: ${{ secrets.AWS_SA_NAMESPACE }}
     steps:
     steps:
-      - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+      - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
         with:
         with:
           egress-policy: audit
           egress-policy: audit
 
 
@@ -169,7 +169,7 @@ jobs:
       GCP_FED_SERVICE_ACCOUNT_EMAIL: ${{ secrets.GCP_FED_SERVICE_ACCOUNT_EMAIL }}
       GCP_FED_SERVICE_ACCOUNT_EMAIL: ${{ secrets.GCP_FED_SERVICE_ACCOUNT_EMAIL }}
       GCP_FED_WORKLOAD_IDENTITY_PROVIDER: ${{ secrets.GCP_FED_WORKLOAD_IDENTITY_PROVIDER }}
       GCP_FED_WORKLOAD_IDENTITY_PROVIDER: ${{ secrets.GCP_FED_WORKLOAD_IDENTITY_PROVIDER }}
     steps:
     steps:
-      - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+      - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
         with:
         with:
           egress-policy: audit
           egress-policy: audit
 
 
@@ -264,7 +264,7 @@ jobs:
       TFC_AZURE_SUBSCRIPTION_ID: ${{ secrets.TFC_AZURE_SUBSCRIPTION_ID }}
       TFC_AZURE_SUBSCRIPTION_ID: ${{ secrets.TFC_AZURE_SUBSCRIPTION_ID }}
       TFC_VAULT_URL: ${{ secrets.TFC_VAULT_URL }}
       TFC_VAULT_URL: ${{ secrets.TFC_VAULT_URL }}
     steps:
     steps:
-      - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+      - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
         with:
         with:
           egress-policy: audit
           egress-policy: audit
 
 

+ 2 - 2
.github/workflows/e2e.yml

@@ -53,7 +53,7 @@ jobs:
       GRAFANA_URL: ${{ secrets.GRAFANA_URL }}
       GRAFANA_URL: ${{ secrets.GRAFANA_URL }}
       GRAFANA_TOKEN: ${{ secrets.GRAFANA_TOKEN }}
       GRAFANA_TOKEN: ${{ secrets.GRAFANA_TOKEN }}
     steps:
     steps:
-    - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+    - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
       with:
       with:
         egress-policy: audit
         egress-policy: audit
 
 
@@ -105,7 +105,7 @@ jobs:
       GRAFANA_URL: ${{ secrets.GRAFANA_URL }}
       GRAFANA_URL: ${{ secrets.GRAFANA_URL }}
       GRAFANA_TOKEN: ${{ secrets.GRAFANA_TOKEN }}
       GRAFANA_TOKEN: ${{ secrets.GRAFANA_TOKEN }}
     steps:
     steps:
-    - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+    - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
       with:
       with:
         egress-policy: audit
         egress-policy: audit
 
 

+ 2 - 2
.github/workflows/helm.yml

@@ -16,7 +16,7 @@ jobs:
     permissions:
     permissions:
       contents: read
       contents: read
     steps:
     steps:
-      - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+      - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
         with:
         with:
           egress-policy: audit
           egress-policy: audit
       - name: Checkout
       - name: Checkout
@@ -71,7 +71,7 @@ jobs:
     runs-on: ubuntu-latest
     runs-on: ubuntu-latest
     steps:
     steps:
       - name: Harden the runner (Audit all outbound calls)
       - name: Harden the runner (Audit all outbound calls)
-        uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+        uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
         with:
         with:
           egress-policy: audit
           egress-policy: audit
 
 

+ 1 - 1
.github/workflows/ok-to-test-managed.yml

@@ -20,7 +20,7 @@ jobs:
     # To create a new GitHub App:
     # To create a new GitHub App:
     #   https://developer.github.com/apps/building-github-apps/creating-a-github-app/
     #   https://developer.github.com/apps/building-github-apps/creating-a-github-app/
     # See app.yml for an example app manifest
     # See app.yml for an example app manifest
-    - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+    - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
       with:
       with:
         egress-policy: audit
         egress-policy: audit
     - name: Generate token
     - name: Generate token

+ 1 - 1
.github/workflows/ok-to-test.yml

@@ -16,7 +16,7 @@ jobs:
     # Only run for PRs, not issue comments
     # Only run for PRs, not issue comments
     if: ${{ github.event.issue.pull_request }}
     if: ${{ github.event.issue.pull_request }}
     steps:
     steps:
-    - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+    - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
       with:
       with:
         egress-policy: audit
         egress-policy: audit
     # Generate a GitHub App installation access token from an App ID and private key
     # Generate a GitHub App installation access token from an App ID and private key

+ 2 - 2
.github/workflows/publish.yml

@@ -53,7 +53,7 @@ jobs:
     outputs:
     outputs:
       image-tag: ${{ steps.container_info.outputs.image-tag }}
       image-tag: ${{ steps.container_info.outputs.image-tag }}
     steps:
     steps:
-      - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+      - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
         with:
         with:
           egress-policy: audit
           egress-policy: audit
 
 
@@ -159,7 +159,7 @@ jobs:
       id-token: write #for keyless sign
       id-token: write #for keyless sign
       packages: write #to update packages with added SBOMs.
       packages: write #to update packages with added SBOMs.
     steps:
     steps:
-      - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+      - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
         with:
         with:
           egress-policy: audit
           egress-policy: audit
       - name: Checkout
       - name: Checkout

+ 1 - 1
.github/workflows/rebuild-image.yml

@@ -19,7 +19,7 @@ jobs:
       timestamp: ${{ steps.timestamp.outputs.timestamp }}
       timestamp: ${{ steps.timestamp.outputs.timestamp }}
 
 
     steps:
     steps:
-      - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+      - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
         with:
         with:
           egress-policy: audit
           egress-policy: audit
       - name: Checkout
       - name: Checkout

+ 2 - 2
.github/workflows/release.yml

@@ -26,7 +26,7 @@ jobs:
       contents: write # to create a release and push new docs
       contents: write # to create a release and push new docs
     steps:
     steps:
       - name: Harden the runner (Audit all outbound calls)
       - name: Harden the runner (Audit all outbound calls)
-        uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+        uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
         with:
         with:
           egress-policy: audit
           egress-policy: audit
 
 
@@ -110,7 +110,7 @@ jobs:
       RELEASE_TAG: ${{ github.event.inputs.version }}${{ matrix.tag_suffix }}
       RELEASE_TAG: ${{ github.event.inputs.version }}${{ matrix.tag_suffix }}
 
 
     steps:
     steps:
-      - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+      - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
         with:
         with:
           egress-policy: audit
           egress-policy: audit
       - name: Checkout
       - name: Checkout

+ 1 - 1
.github/workflows/release_esoctl.yml

@@ -24,7 +24,7 @@ jobs:
     permissions:
     permissions:
       contents: write # for publishing the release
       contents: write # for publishing the release
     steps:
     steps:
-      - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+      - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
         with:
         with:
           egress-policy: audit
           egress-policy: audit
       - name: Checkout
       - name: Checkout

+ 1 - 1
.github/workflows/scorecard.yml

@@ -20,7 +20,7 @@ jobs:
       id-token: write
       id-token: write
 
 
     steps:
     steps:
-      - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+      - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
         with:
         with:
           egress-policy: audit
           egress-policy: audit
       - name: "Checkout code"
       - name: "Checkout code"

+ 1 - 1
.github/workflows/stale.yml

@@ -13,7 +13,7 @@ jobs:
       pull-requests: write  # for actions/stale to close stale PRs
       pull-requests: write  # for actions/stale to close stale PRs
     runs-on: ubuntu-latest
     runs-on: ubuntu-latest
     steps:
     steps:
-      - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+      - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
         with:
         with:
           egress-policy: audit
           egress-policy: audit
       - uses: actions/stale@b5d41d4e1d5dceea10e7104786b73624c18a190f # v10.2.0
       - uses: actions/stale@b5d41d4e1d5dceea10e7104786b73624c18a190f # v10.2.0

+ 2 - 2
.github/workflows/update-deps.yml

@@ -20,7 +20,7 @@ jobs:
       branches: ${{ steps.branches.outputs.branches }}
       branches: ${{ steps.branches.outputs.branches }}
 
 
     steps:
     steps:
-      - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+      - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
         with:
         with:
           egress-policy: audit
           egress-policy: audit
       - name: Checkout
       - name: Checkout
@@ -42,7 +42,7 @@ jobs:
       matrix:
       matrix:
         branch: ${{ fromJson(needs.branches.outputs.branches) }}
         branch: ${{ fromJson(needs.branches.outputs.branches) }}
     steps:
     steps:
-    - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+    - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
       with:
       with:
         egress-policy: audit
         egress-policy: audit
 
 

+ 1 - 1
.github/workflows/zizmor.yml

@@ -24,7 +24,7 @@ jobs:
     outputs:
     outputs:
       noop: ${{ steps.noop.outputs.should_skip }}
       noop: ${{ steps.noop.outputs.should_skip }}
     steps:
     steps:
-      - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
+      - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
         with:
         with:
           egress-policy: audit
           egress-policy: audit
       - name: Detect No-op Changes
       - name: Detect No-op Changes