From 7366fd8b0d3da87e13e28a0ccf08998bad569021 Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Wed, 11 Sep 2024 00:05:07 +0000 Subject: [PATCH] chore(deps): update step-security/harden-runner action to v2.10.0 --- .github/workflows/bank.f5labs.dev-k6-tests.yaml | 2 +- .github/workflows/bank.f5labs.dev-zap-baseline.yml | 2 +- .github/workflows/bank.f5labs.dev-zap-full.yml | 2 +- .github/workflows/github-issue-labeler.yml | 2 +- .github/workflows/github-tag-for-deployment.yml | 2 +- .github/workflows/gql.f5labs.dev-zap-baseline.yml | 2 +- .github/workflows/gql.f5labs.dev-zap-full.yml | 2 +- .github/workflows/hapi.f5labs.dev-newman-tests.yaml | 2 +- .github/workflows/hapi.f5labs.dev-zap-api.yml | 2 +- .github/workflows/hapi.f5labs.dev-zap-baseline.yml | 2 +- .github/workflows/hapi.f5labs.dev-zap-full.yml | 2 +- .github/workflows/secops-code-scan.yml | 2 +- .github/workflows/secops-dependency-review.yml | 2 +- .github/workflows/secops-scorecard.yml | 2 +- 14 files changed, 14 insertions(+), 14 deletions(-) diff --git a/.github/workflows/bank.f5labs.dev-k6-tests.yaml b/.github/workflows/bank.f5labs.dev-k6-tests.yaml index 35d38b905..8e64ee253 100644 --- a/.github/workflows/bank.f5labs.dev-k6-tests.yaml +++ b/.github/workflows/bank.f5labs.dev-k6-tests.yaml @@ -9,7 +9,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Harden Runner - uses: step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9.1 + uses: step-security/harden-runner@446798f8213ac2e75931c1b0769676d927801858 # v2.10.0 with: disable-sudo: true egress-policy: block diff --git a/.github/workflows/bank.f5labs.dev-zap-baseline.yml b/.github/workflows/bank.f5labs.dev-zap-baseline.yml index 6a5a356b6..d3e83b4dd 100644 --- a/.github/workflows/bank.f5labs.dev-zap-baseline.yml +++ b/.github/workflows/bank.f5labs.dev-zap-baseline.yml @@ -14,7 +14,7 @@ jobs: issues: write steps: - name: Harden Runner - uses: step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9.1 + uses: step-security/harden-runner@446798f8213ac2e75931c1b0769676d927801858 # v2.10.0 with: egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs - name: ZAP Scan diff --git a/.github/workflows/bank.f5labs.dev-zap-full.yml b/.github/workflows/bank.f5labs.dev-zap-full.yml index b7db86b5c..8bed60fb2 100644 --- a/.github/workflows/bank.f5labs.dev-zap-full.yml +++ b/.github/workflows/bank.f5labs.dev-zap-full.yml @@ -14,7 +14,7 @@ jobs: issues: write steps: - name: Harden Runner - uses: step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9.1 + uses: step-security/harden-runner@446798f8213ac2e75931c1b0769676d927801858 # v2.10.0 with: egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs - name: ZAP Scan diff --git a/.github/workflows/github-issue-labeler.yml b/.github/workflows/github-issue-labeler.yml index 572d7075e..0e09c4d21 100644 --- a/.github/workflows/github-issue-labeler.yml +++ b/.github/workflows/github-issue-labeler.yml @@ -13,7 +13,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Harden Runner - uses: step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9.1 + uses: step-security/harden-runner@446798f8213ac2e75931c1b0769676d927801858 # v2.10.0 with: egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs - uses: github/issue-labeler@v3.4 #May not be the latest version diff --git a/.github/workflows/github-tag-for-deployment.yml b/.github/workflows/github-tag-for-deployment.yml index 82381aa84..7abe9b2e6 100644 --- a/.github/workflows/github-tag-for-deployment.yml +++ b/.github/workflows/github-tag-for-deployment.yml @@ -14,7 +14,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Harden Runner - uses: step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9.1 + uses: step-security/harden-runner@446798f8213ac2e75931c1b0769676d927801858 # v2.10.0 with: egress-policy: audit - name: Checkout repository diff --git a/.github/workflows/gql.f5labs.dev-zap-baseline.yml b/.github/workflows/gql.f5labs.dev-zap-baseline.yml index 29f84dcdb..c21dd1aeb 100644 --- a/.github/workflows/gql.f5labs.dev-zap-baseline.yml +++ b/.github/workflows/gql.f5labs.dev-zap-baseline.yml @@ -14,7 +14,7 @@ jobs: issues: write steps: - name: Harden Runner - uses: step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9.1 + uses: step-security/harden-runner@446798f8213ac2e75931c1b0769676d927801858 # v2.10.0 with: egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs - name: ZAP Scan diff --git a/.github/workflows/gql.f5labs.dev-zap-full.yml b/.github/workflows/gql.f5labs.dev-zap-full.yml index f8f41f429..f2fa3e345 100644 --- a/.github/workflows/gql.f5labs.dev-zap-full.yml +++ b/.github/workflows/gql.f5labs.dev-zap-full.yml @@ -14,7 +14,7 @@ jobs: issues: write steps: - name: Harden Runner - uses: step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9.1 + uses: step-security/harden-runner@446798f8213ac2e75931c1b0769676d927801858 # v2.10.0 with: egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs - name: ZAP Scan diff --git a/.github/workflows/hapi.f5labs.dev-newman-tests.yaml b/.github/workflows/hapi.f5labs.dev-newman-tests.yaml index 343d46e2b..14f5db326 100644 --- a/.github/workflows/hapi.f5labs.dev-newman-tests.yaml +++ b/.github/workflows/hapi.f5labs.dev-newman-tests.yaml @@ -9,7 +9,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Harden Runner - uses: step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9.1 + uses: step-security/harden-runner@446798f8213ac2e75931c1b0769676d927801858 # v2.10.0 with: disable-sudo: true egress-policy: block diff --git a/.github/workflows/hapi.f5labs.dev-zap-api.yml b/.github/workflows/hapi.f5labs.dev-zap-api.yml index a35b462e0..802c73dfc 100644 --- a/.github/workflows/hapi.f5labs.dev-zap-api.yml +++ b/.github/workflows/hapi.f5labs.dev-zap-api.yml @@ -14,7 +14,7 @@ jobs: issues: write steps: - name: Harden Runner - uses: step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9.1 + uses: step-security/harden-runner@446798f8213ac2e75931c1b0769676d927801858 # v2.10.0 with: egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs - name: Checkout diff --git a/.github/workflows/hapi.f5labs.dev-zap-baseline.yml b/.github/workflows/hapi.f5labs.dev-zap-baseline.yml index 6b7046723..dcd7715ed 100644 --- a/.github/workflows/hapi.f5labs.dev-zap-baseline.yml +++ b/.github/workflows/hapi.f5labs.dev-zap-baseline.yml @@ -14,7 +14,7 @@ jobs: issues: write steps: - name: Harden Runner - uses: step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9.1 + uses: step-security/harden-runner@446798f8213ac2e75931c1b0769676d927801858 # v2.10.0 with: egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs - name: ZAP Scan diff --git a/.github/workflows/hapi.f5labs.dev-zap-full.yml b/.github/workflows/hapi.f5labs.dev-zap-full.yml index 308b62f89..d1a368c36 100644 --- a/.github/workflows/hapi.f5labs.dev-zap-full.yml +++ b/.github/workflows/hapi.f5labs.dev-zap-full.yml @@ -14,7 +14,7 @@ jobs: issues: write steps: - name: Harden Runner - uses: step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9.1 + uses: step-security/harden-runner@446798f8213ac2e75931c1b0769676d927801858 # v2.10.0 with: egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs - name: ZAP Scan diff --git a/.github/workflows/secops-code-scan.yml b/.github/workflows/secops-code-scan.yml index 28509e4fa..a520b15ab 100644 --- a/.github/workflows/secops-code-scan.yml +++ b/.github/workflows/secops-code-scan.yml @@ -29,7 +29,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Harden Runner - uses: step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9.1 + uses: step-security/harden-runner@446798f8213ac2e75931c1b0769676d927801858 # v2.10.0 with: disable-sudo: true egress-policy: block diff --git a/.github/workflows/secops-dependency-review.yml b/.github/workflows/secops-dependency-review.yml index 1aeff0431..6796dc2dc 100644 --- a/.github/workflows/secops-dependency-review.yml +++ b/.github/workflows/secops-dependency-review.yml @@ -15,7 +15,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Harden Runner - uses: step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9.1 + uses: step-security/harden-runner@446798f8213ac2e75931c1b0769676d927801858 # v2.10.0 with: disable-sudo: true egress-policy: block diff --git a/.github/workflows/secops-scorecard.yml b/.github/workflows/secops-scorecard.yml index 1d4fa6463..af42065be 100644 --- a/.github/workflows/secops-scorecard.yml +++ b/.github/workflows/secops-scorecard.yml @@ -28,7 +28,7 @@ jobs: actions: read steps: - name: Harden Runner - uses: step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9.1 + uses: step-security/harden-runner@446798f8213ac2e75931c1b0769676d927801858 # v2.10.0 with: egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs - name: "Checkout code"