diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 3649a784..7b23335f 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -43,7 +43,7 @@ jobs: image: ${{ inputs.arch == 'x86_64' && 'fedora:44@sha256:f717d3f59ea0dc45d3c024c9477e786bab7d418d26636920d17b48016f1e69ca' || 'fedora:44@sha256:63a832c5308c808ecee9a90a0459f67beee9205db01bd967bde410429cd33fc0' }} steps: - name: Enable egress auditing - uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2.19.1 + uses: step-security/harden-runner@9ca718d3bf646d6534007c269a635b3e54cadf99 # v2.19.2 with: egress-policy: audit @@ -83,7 +83,7 @@ jobs: options: --privileged steps: - name: Enable egress auditing - uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2.19.1 + uses: step-security/harden-runner@9ca718d3bf646d6534007c269a635b3e54cadf99 # v2.19.2 with: egress-policy: audit @@ -141,7 +141,7 @@ jobs: hashes: ${{ steps.sign.outputs.hashes }} steps: - name: Enable egress auditing - uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2.19.1 + uses: step-security/harden-runner@9ca718d3bf646d6534007c269a635b3e54cadf99 # v2.19.2 with: egress-policy: audit