7f3d8a34e2d850b51782f0900151413b435296d4

Author
StepSecurity Bot <bot@stepsecurity.io>
Committer
GitHub <noreply@github.com>
Date

Message

ci: Harden GitHub Actions [StepSecurity] (#13318)

Diff

  1diff --git a/.github/workflows/dependencies.yml b/.github/workflows/dependencies.yml
  2index 11c0ad0ef9ff4acaaaf6a9f197f72313742e1153..3f448fe64c1de5ede91076a8e86bffa9401985fd 100644
  3--- a/.github/workflows/dependencies.yml
  4+++ b/.github/workflows/dependencies.yml
  5@@ -13,18 +13,23 @@ jobs:
  6     runs-on: ubuntu-latest
  7     if: github.repository == 'ohmyzsh/ohmyzsh'
  8     steps:
  9+      - name: Harden the runner (Audit all outbound calls)
 10+        uses: step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
 11+        with:
 12+          egress-policy: audit
 13+
 14       - name: Checkout
 15-        uses: actions/checkout@v5
 16+        uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
 17         with:
 18           fetch-depth: 0
 19       - name: Authenticate as @ohmyzsh
 20         id: generate-token
 21-        uses: actions/create-github-app-token@v2
 22+        uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4
 23         with:
 24           app-id: ${{ secrets.OHMYZSH_APP_ID }}
 25           private-key: ${{ secrets.OHMYZSH_APP_PRIVATE_KEY }}
 26       - name: Setup Python
 27-        uses: actions/setup-python@v6
 28+        uses: actions/setup-python@e797f83bcb11b83ae66e0230d6156d7c80228e7c # v6.0.0
 29         with:
 30           python-version: "3.12"
 31           cache: "pip"
 32diff --git a/.github/workflows/installer.yml b/.github/workflows/installer.yml
 33index 9e933350f85905e11e6a4be95c22ee27fadb9fe0..2d1de706a038b08d43cc59f7cc8e273b8c6db62b 100644
 34--- a/.github/workflows/installer.yml
 35+++ b/.github/workflows/installer.yml
 36@@ -25,8 +25,13 @@ jobs:
 37           - ubuntu-latest
 38           - macos-latest
 39     steps:
 40+      - name: Harden the runner (Audit all outbound calls)
 41+        uses: step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
 42+        with:
 43+          egress-policy: audit
 44+
 45       - name: Set up git repository
 46-        uses: actions/checkout@v5
 47+        uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
 48       - name: Install zsh
 49         if: runner.os == 'Linux'
 50         run: sudo apt-get update; sudo apt-get install zsh
 51@@ -41,8 +46,13 @@ jobs:
 52     needs:
 53       - test
 54     steps:
 55+      - name: Harden the runner (Audit all outbound calls)
 56+        uses: step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
 57+        with:
 58+          egress-policy: audit
 59+
 60       - name: Checkout
 61-        uses: actions/checkout@v5
 62+        uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
 63       - name: Install Vercel CLI
 64         run: npm install -g vercel
 65       - name: Setup project and deploy
 66diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml
 67index c49324495d54befd6c0ddce48afa815cc8d53665..b48a3d32beae94565aa37923405e9863a4ccadea 100644
 68--- a/.github/workflows/main.yml
 69+++ b/.github/workflows/main.yml
 70@@ -23,8 +23,13 @@ jobs:
 71     runs-on: ubuntu-latest
 72     if: github.repository == 'ohmyzsh/ohmyzsh'
 73     steps:
 74+      - name: Harden the runner (Audit all outbound calls)
 75+        uses: step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
 76+        with:
 77+          egress-policy: audit
 78+
 79       - name: Set up git repository
 80-        uses: actions/checkout@v5
 81+        uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
 82       - name: Install zsh
 83         run: sudo apt-get update; sudo apt-get install zsh
 84       - name: Check syntax
 85diff --git a/.github/workflows/project.yml b/.github/workflows/project.yml
 86index 8fd4e15d46e3d6ea14cf91d0cb7a944447ba2fea..ba971db15c4eaa3d0d92a1816632888cfef201d1 100644
 87--- a/.github/workflows/project.yml
 88+++ b/.github/workflows/project.yml
 89@@ -16,9 +16,14 @@ jobs:
 90     runs-on: ubuntu-latest
 91     if: github.repository == 'ohmyzsh/ohmyzsh'
 92     steps:
 93+      - name: Harden the runner (Audit all outbound calls)
 94+        uses: step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
 95+        with:
 96+          egress-policy: audit
 97+
 98       - name: Authenticate as @ohmyzsh
 99         id: generate-token
100-        uses: actions/create-github-app-token@v2
101+        uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4
102         with:
103           app-id: ${{ secrets.OHMYZSH_APP_ID }}
104           private-key: ${{ secrets.OHMYZSH_APP_PRIVATE_KEY }}