|
@@ -28,7 +28,7 @@ jobs:
|
|
|
outputs:
|
|
outputs:
|
|
|
check_run_id: ${{ steps.create_check.outputs.check_run_id }}
|
|
check_run_id: ${{ steps.create_check.outputs.check_run_id }}
|
|
|
steps:
|
|
steps:
|
|
|
- - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
|
|
|
|
|
|
|
+ - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
|
|
|
with:
|
|
with:
|
|
|
egress-policy: audit
|
|
egress-policy: audit
|
|
|
|
|
|
|
@@ -82,7 +82,7 @@ jobs:
|
|
|
TF_VAR_AWS_SA_NAME: ${{ secrets.AWS_SA_NAME }}
|
|
TF_VAR_AWS_SA_NAME: ${{ secrets.AWS_SA_NAME }}
|
|
|
TF_VAR_AWS_SA_NAMESPACE: ${{ secrets.AWS_SA_NAMESPACE }}
|
|
TF_VAR_AWS_SA_NAMESPACE: ${{ secrets.AWS_SA_NAMESPACE }}
|
|
|
steps:
|
|
steps:
|
|
|
- - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
|
|
|
|
|
|
|
+ - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
|
|
|
with:
|
|
with:
|
|
|
egress-policy: audit
|
|
egress-policy: audit
|
|
|
|
|
|
|
@@ -169,7 +169,7 @@ jobs:
|
|
|
GCP_FED_SERVICE_ACCOUNT_EMAIL: ${{ secrets.GCP_FED_SERVICE_ACCOUNT_EMAIL }}
|
|
GCP_FED_SERVICE_ACCOUNT_EMAIL: ${{ secrets.GCP_FED_SERVICE_ACCOUNT_EMAIL }}
|
|
|
GCP_FED_WORKLOAD_IDENTITY_PROVIDER: ${{ secrets.GCP_FED_WORKLOAD_IDENTITY_PROVIDER }}
|
|
GCP_FED_WORKLOAD_IDENTITY_PROVIDER: ${{ secrets.GCP_FED_WORKLOAD_IDENTITY_PROVIDER }}
|
|
|
steps:
|
|
steps:
|
|
|
- - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
|
|
|
|
|
|
|
+ - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
|
|
|
with:
|
|
with:
|
|
|
egress-policy: audit
|
|
egress-policy: audit
|
|
|
|
|
|
|
@@ -264,7 +264,7 @@ jobs:
|
|
|
TFC_AZURE_SUBSCRIPTION_ID: ${{ secrets.TFC_AZURE_SUBSCRIPTION_ID }}
|
|
TFC_AZURE_SUBSCRIPTION_ID: ${{ secrets.TFC_AZURE_SUBSCRIPTION_ID }}
|
|
|
TFC_VAULT_URL: ${{ secrets.TFC_VAULT_URL }}
|
|
TFC_VAULT_URL: ${{ secrets.TFC_VAULT_URL }}
|
|
|
steps:
|
|
steps:
|
|
|
- - uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2.16.1
|
|
|
|
|
|
|
+ - uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
|
|
|
with:
|
|
with:
|
|
|
egress-policy: audit
|
|
egress-policy: audit
|
|
|
|
|
|