From 8b7e2a634c729ea0e0bc74cf0df860e70bcd7a13 Mon Sep 17 00:00:00 2001 From: StepSecurity Bot Date: Mon, 3 Mar 2025 16:52:50 +0000 Subject: [PATCH 1/2] [StepSecurity] ci: Harden GitHub Actions Signed-off-by: StepSecurity Bot --- .github/workflows/runs-on.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/runs-on.yml b/.github/workflows/runs-on.yml index 319b915..a233b74 100644 --- a/.github/workflows/runs-on.yml +++ b/.github/workflows/runs-on.yml @@ -3,6 +3,9 @@ name: RunsOn Tests on: workflow_dispatch: +permissions: + contents: read + jobs: test-host-outbound: runs-on: From e34e1ce8690e18d015d2271cd5bccbfc9aec6905 Mon Sep 17 00:00:00 2001 From: Michael Vorburger Date: Tue, 4 Mar 2025 05:48:31 +0100 Subject: [PATCH 2/2] Update actions/upload-artifact in Scorecards from v3.0.0 to v4.6.1 Prompted by https://github.com/MariaDB4j/MariaDB4j/issues/1107, due to https://github.blog/changelog/2024-04-16-deprecation-notice-v3-of-the-artifact-actions/. --- .github/workflows/scorecards.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/scorecards.yml b/.github/workflows/scorecards.yml index e694a29..f5deaae 100644 --- a/.github/workflows/scorecards.yml +++ b/.github/workflows/scorecards.yml @@ -54,7 +54,7 @@ jobs: # Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF # format to the repository Actions tab. - name: "Upload artifact" - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # tag=v3.0.0 + uses: actions/upload-artifact@4cec3d8aa04e39d1a68397de0c4cd6fb9dce8ec1 # tag=v4.6.1 with: name: SARIF file path: results.sarif