|
42 | 42 | outputs: |
43 | 43 | test_names: ${{ steps.set_test_names.outputs.test_names }} |
44 | 44 | steps: |
| 45 | + - name: Harden Runner |
| 46 | + uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1 |
| 47 | + with: |
| 48 | + egress-policy: audit |
45 | 49 | - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 |
46 | 50 |
|
47 | 51 | - id: setup_golang |
|
80 | 84 | gke: ${{ steps.set-versions.outputs.gke }} |
81 | 85 | istio: ${{ steps.set-versions.outputs.istio }} |
82 | 86 | steps: |
| 87 | + - name: Harden Runner |
| 88 | + uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1 |
| 89 | + with: |
| 90 | + egress-policy: audit |
83 | 91 | - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 |
84 | 92 |
|
85 | 93 | - id: set-versions |
@@ -107,6 +115,10 @@ jobs: |
107 | 115 | kubernetes-version: ${{ fromJSON(needs.dependencies-versions.outputs.kind) }} |
108 | 116 | test: ${{ fromJSON(needs.setup-e2e-tests.outputs.test_names) }} |
109 | 117 | steps: |
| 118 | + - name: Harden Runner |
| 119 | + uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1 |
| 120 | + with: |
| 121 | + egress-policy: audit |
110 | 122 | - name: Download built image artifact |
111 | 123 | if: ${{ inputs.load-local-image }} |
112 | 124 | uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0 |
@@ -223,6 +235,10 @@ jobs: |
223 | 235 | kubernetes-version: ${{ fromJSON(needs.dependencies-versions.outputs.gke) }} |
224 | 236 | test: ${{ fromJSON(needs.setup-e2e-tests.outputs.test_names) }} |
225 | 237 | steps: |
| 238 | + - name: Harden Runner |
| 239 | + uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1 |
| 240 | + with: |
| 241 | + egress-policy: audit |
226 | 242 | - name: checkout repository |
227 | 243 | uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 |
228 | 244 |
|
@@ -339,6 +355,10 @@ jobs: |
339 | 355 | matrix: |
340 | 356 | include: ${{ fromJSON(needs.dependencies-versions.outputs.istio) }} |
341 | 357 | steps: |
| 358 | + - name: Harden Runner |
| 359 | + uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1 |
| 360 | + with: |
| 361 | + egress-policy: audit |
342 | 362 | - name: Download built image artifact |
343 | 363 | if: ${{ inputs.load-local-image }} |
344 | 364 | uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0 |
|
0 commit comments