3535 contents : read
3636 steps :
3737 - name : " 🔒 Harden Runner"
38- uses : step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
38+ uses : step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
3939 with :
4040 disable-sudo : true
4141 egress-policy : block
@@ -98,13 +98,13 @@ jobs:
9898 *.actions.githubusercontent.com:443
9999 *.blob.core.windows.net:443
100100 - name : " 📂 Checkout Repository Code"
101- uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
101+ uses : actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
102102 with :
103103 persist-credentials : false
104104
105105 - name : " 🔍 Dependency Review"
106106 if : github.event_name == 'pull_request'
107- uses : actions/dependency-review-action@2031cfc080254a8a887f58cffee85186f0e49e48 # v4.9 .0
107+ uses : actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5.0 .0
108108
109109 # 1. Code Quality Stage (Lint)
110110 lint :
@@ -130,7 +130,7 @@ jobs:
130130 steps :
131131 - name : " 🔒 Harden Runner"
132132 if : matrix.os == 'ubuntu-latest'
133- uses : step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
133+ uses : step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
134134 with :
135135 disable-sudo : true
136136 egress-policy : block
@@ -193,7 +193,7 @@ jobs:
193193 *.actions.githubusercontent.com:443
194194 *.blob.core.windows.net:443
195195 - name : " 📂 Checkout Repository Code"
196- uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
196+ uses : actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
197197 with :
198198 persist-credentials : false
199199
@@ -239,7 +239,7 @@ jobs:
239239 steps :
240240 - name : " 🔒 Harden Runner"
241241 if : matrix.os == 'ubuntu-latest'
242- uses : step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
242+ uses : step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
243243 with :
244244 disable-sudo : true
245245 egress-policy : block
@@ -302,7 +302,7 @@ jobs:
302302 *.actions.githubusercontent.com:443
303303 *.blob.core.windows.net:443
304304 - name : " 📂 Checkout Repository Code"
305- uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
305+ uses : actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
306306 with :
307307 persist-credentials : false
308308
@@ -389,7 +389,7 @@ jobs:
389389 PYTHONUTF8 : 1
390390 steps :
391391 - name : " 🔒 Harden Runner"
392- uses : step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
392+ uses : step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
393393 with :
394394 disable-sudo : true
395395 egress-policy : block
@@ -452,7 +452,7 @@ jobs:
452452 *.actions.githubusercontent.com:443
453453 *.blob.core.windows.net:443
454454 - name : " 📂 Checkout Repository Code"
455- uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
455+ uses : actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
456456 with :
457457 persist-credentials : false
458458 fetch-depth : 0
@@ -509,7 +509,7 @@ jobs:
509509 GITHUB_TOKEN : ${{ secrets.WORKFLOW_SECRET || secrets.GITHUB_TOKEN }}
510510
511511 - name : " 🕵️ Detect Vulnerabilities (Trivy FS)"
512- uses : aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # v0.35 .0
512+ uses : aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36 .0
513513 if : ${{ always() }}
514514 env :
515515 TRIVY_DB_REPOSITORY : " public.ecr.aws/aquasecurity/trivy-db"
0 commit comments