Diff
1diff --git a/.github/workflows/dependencies.yml b/.github/workflows/dependencies.yml
2index ab5272965f0f92d66a11cecc51cac8d01273f8d7..212cfbf048203e009c1c31bfd89b431a6562598e 100644
3--- a/.github/workflows/dependencies.yml
4+++ b/.github/workflows/dependencies.yml
5@@ -16,7 +16,7 @@ jobs:
6 contents: write # this is needed to push commits and branches
7 steps:
8 - name: Harden the runner (Audit all outbound calls)
9- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
10+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
11 with:
12 egress-policy: audit
13
14diff --git a/.github/workflows/installer.yml b/.github/workflows/installer.yml
15index 916cb781a63011801d57f008ba5aa20ad94f4b72..04acc67acf53f52605ee51860607fbc232909a51 100644
16--- a/.github/workflows/installer.yml
17+++ b/.github/workflows/installer.yml
18@@ -26,7 +26,7 @@ jobs:
19 - macos-latest
20 steps:
21 - name: Harden the runner (Audit all outbound calls)
22- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
23+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
24 with:
25 egress-policy: audit
26
27@@ -47,7 +47,7 @@ jobs:
28 - test
29 steps:
30 - name: Harden the runner (Audit all outbound calls)
31- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
32+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
33 with:
34 egress-policy: audit
35
36diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml
37index 93a25d6d2044c6cbdb09bb78b4bbc62e35dd0939..8b83613dacda099b60b709f9e9f23c2b3f9fa6b0 100644
38--- a/.github/workflows/main.yml
39+++ b/.github/workflows/main.yml
40@@ -24,7 +24,7 @@ jobs:
41 if: github.repository == 'ohmyzsh/ohmyzsh'
42 steps:
43 - name: Harden the runner (Audit all outbound calls)
44- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
45+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
46 with:
47 egress-policy: audit
48
49diff --git a/.github/workflows/project.yml b/.github/workflows/project.yml
50index b9489cf6fba42cd58033a0d1d8a6e68ddfe4c4dd..f6daabdb25c6a66d189bf098b750c87850962eca 100644
51--- a/.github/workflows/project.yml
52+++ b/.github/workflows/project.yml
53@@ -17,7 +17,7 @@ jobs:
54 if: github.repository == 'ohmyzsh/ohmyzsh'
55 steps:
56 - name: Harden the runner (Audit all outbound calls)
57- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
58+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
59 with:
60 egress-policy: audit
61 - name: Authenticate as @ohmyzsh
62diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml
63index c2d50610862c17988e75709bd0349f5863e48577..ca577b9aca07dab997cf72beda5caa195588a596 100644
64--- a/.github/workflows/scorecard.yml
65+++ b/.github/workflows/scorecard.yml
66@@ -36,7 +36,7 @@ jobs:
67
68 steps:
69 - name: Harden the runner (Audit all outbound calls)
70- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
71+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
72 with:
73 egress-policy: audit
74
75@@ -60,6 +60,6 @@ jobs:
76 retention-days: 5
77
78 - name: "Upload to code-scanning"
79- uses: github/codeql-action/upload-sarif@f205ea1c3313d32999d8d6a48b4f6530d4437b38 # v4.37.4
80+ uses: github/codeql-action/upload-sarif@5595ccaf912efad79be6eef63a5619ff05969be3 # v4.37.6
81 with:
82 sarif_file: results.sarif