From cecf84878d5295040f6d8006d81c2efc52322bcd Mon Sep 17 00:00:00 2001 From: Shivam Mathur Date: Tue, 7 Dec 2021 21:26:23 +0530 Subject: [PATCH] Update Harden Runner step in node workflows --- .github/workflows/node-release.yml | 7 ++++++- .github/workflows/node-workflow.yml | 4 +--- 2 files changed, 7 insertions(+), 4 deletions(-) diff --git a/.github/workflows/node-release.yml b/.github/workflows/node-release.yml index 6a49777d..d207436c 100644 --- a/.github/workflows/node-release.yml +++ b/.github/workflows/node-release.yml @@ -18,7 +18,12 @@ jobs: packages: write steps: - name: Harden Runner - uses: step-security/harden-runner@main + uses: step-security/harden-runner@v1 + with: + allowed-endpoints: + github.com:443 + npm.pkg.github.com:443 + registry.npmjs.org:443 - name: Checkout release if: github.event_name != 'workflow_dispatch' diff --git a/.github/workflows/node-workflow.yml b/.github/workflows/node-workflow.yml index 1e9ccc6b..a9286a4b 100644 --- a/.github/workflows/node-workflow.yml +++ b/.github/workflows/node-workflow.yml @@ -26,11 +26,9 @@ jobs: operating-system: [ubuntu-latest, windows-latest, macos-latest] steps: - name: Harden Runner - if: runner.os == 'Linux' - uses: step-security/harden-runner@main + uses: step-security/harden-runner@v1 with: allowed-endpoints: - beta.api.stepsecurity.io.:443 codecov.io.:443 github.com.:443 nodejs.org.:443