Diff
1diff --git a/.github/workflows/dependencies.yml b/.github/workflows/dependencies.yml
2index 86f5d2f05bf221eb059361dd25ec0560ed8389b9..027c2c755baa2352f4b50ea2cc986509385bea9b 100644
3--- a/.github/workflows/dependencies.yml
4+++ b/.github/workflows/dependencies.yml
5@@ -13,7 +13,7 @@ jobs:
6 contents: write # this is needed to push commits and branches
7 steps:
8 - name: Harden the runner (Audit all outbound calls)
9- uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2.14.1
10+ uses: step-security/harden-runner@5ef0c079ce82195b2a36a210272d6b661572d83e # v2.14.2
11 with:
12 egress-policy: audit
13
14diff --git a/.github/workflows/installer.yml b/.github/workflows/installer.yml
15index 9277491c63b5da944bf81dfba4aabe36168eda0f..62a736471ce1aaf97db4176a6248bdd8b4ad5799 100644
16--- a/.github/workflows/installer.yml
17+++ b/.github/workflows/installer.yml
18@@ -26,7 +26,7 @@ jobs:
19 - macos-latest
20 steps:
21 - name: Harden the runner (Audit all outbound calls)
22- uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2.14.1
23+ uses: step-security/harden-runner@5ef0c079ce82195b2a36a210272d6b661572d83e # v2.14.2
24 with:
25 egress-policy: audit
26
27@@ -47,7 +47,7 @@ jobs:
28 - test
29 steps:
30 - name: Harden the runner (Audit all outbound calls)
31- uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2.14.1
32+ uses: step-security/harden-runner@5ef0c079ce82195b2a36a210272d6b661572d83e # v2.14.2
33 with:
34 egress-policy: audit
35
36diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml
37index c0973c52d9bf2632aec91fcaf01ca4bedd4e337c..0fb18b42fc60c3e78b1aca0645e87da8995bf7d1 100644
38--- a/.github/workflows/main.yml
39+++ b/.github/workflows/main.yml
40@@ -24,7 +24,7 @@ jobs:
41 if: github.repository == 'ohmyzsh/ohmyzsh'
42 steps:
43 - name: Harden the runner (Audit all outbound calls)
44- uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2.14.1
45+ uses: step-security/harden-runner@5ef0c079ce82195b2a36a210272d6b661572d83e # v2.14.2
46 with:
47 egress-policy: audit
48
49diff --git a/.github/workflows/project.yml b/.github/workflows/project.yml
50index f84e09d46e37215419ebfac4339b36f556239d71..b0c018d77d8e34d995aad6f3f896cc5c673a9b47 100644
51--- a/.github/workflows/project.yml
52+++ b/.github/workflows/project.yml
53@@ -17,7 +17,7 @@ jobs:
54 if: github.repository == 'ohmyzsh/ohmyzsh'
55 steps:
56 - name: Harden the runner (Audit all outbound calls)
57- uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2.14.1
58+ uses: step-security/harden-runner@5ef0c079ce82195b2a36a210272d6b661572d83e # v2.14.2
59 with:
60 egress-policy: audit
61 - name: Authenticate as @ohmyzsh
62diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml
63index 1cf5a801e3d4861841bca2e3628ce263bbbb2404..3fa953d5664abf64b4f8b623a703fbf6d25c63b5 100644
64--- a/.github/workflows/scorecard.yml
65+++ b/.github/workflows/scorecard.yml
66@@ -36,7 +36,7 @@ jobs:
67
68 steps:
69 - name: Harden the runner (Audit all outbound calls)
70- uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2.14.1
71+ uses: step-security/harden-runner@5ef0c079ce82195b2a36a210272d6b661572d83e # v2.14.2
72 with:
73 egress-policy: audit
74