diff --git a/.github/workflows/ci_tests.yml b/.github/workflows/ci_tests.yml index 736049d..412189a 100644 --- a/.github/workflows/ci_tests.yml +++ b/.github/workflows/ci_tests.yml @@ -14,10 +14,10 @@ permissions: read-all jobs: beman-submodule-check: - uses: bemanproject/infra-workflows/.github/workflows/reusable-beman-submodule-check.yml@4d946e210ce2ee68ccd8607c8acccacf171830c5 # ratchet:bemanproject/infra-workflows/.github/workflows/reusable-beman-submodule-check.yml@1.7.1 + uses: bemanproject/infra-workflows/.github/workflows/reusable-beman-submodule-check.yml@b83fb68ccf4644e9185a2e016b7e6dfccc88a06c # ratchet:bemanproject/infra-workflows/.github/workflows/reusable-beman-submodule-check.yml@1.7.2 preset-test: - uses: bemanproject/infra-workflows/.github/workflows/reusable-beman-preset-test.yml@4d946e210ce2ee68ccd8607c8acccacf171830c5 # ratchet:bemanproject/infra-workflows/.github/workflows/reusable-beman-preset-test.yml@1.7.1 + uses: bemanproject/infra-workflows/.github/workflows/reusable-beman-preset-test.yml@b83fb68ccf4644e9185a2e016b7e6dfccc88a06c # ratchet:bemanproject/infra-workflows/.github/workflows/reusable-beman-preset-test.yml@1.7.2 with: matrix_config: > [ @@ -32,7 +32,7 @@ jobs: ] build-and-test: - uses: bemanproject/infra-workflows/.github/workflows/reusable-beman-build-and-test.yml@4d946e210ce2ee68ccd8607c8acccacf171830c5 # ratchet:bemanproject/infra-workflows/.github/workflows/reusable-beman-build-and-test.yml@1.7.1 + uses: bemanproject/infra-workflows/.github/workflows/reusable-beman-build-and-test.yml@b83fb68ccf4644e9185a2e016b7e6dfccc88a06c # ratchet:bemanproject/infra-workflows/.github/workflows/reusable-beman-build-and-test.yml@1.7.2 with: matrix_config: > { @@ -120,4 +120,4 @@ jobs: create-issue-when-fault: needs: [preset-test, build-and-test] if: failure() && github.event_name == 'schedule' - uses: bemanproject/infra-workflows/.github/workflows/reusable-beman-create-issue-when-fault.yml@4d946e210ce2ee68ccd8607c8acccacf171830c5 # ratchet:bemanproject/infra-workflows/.github/workflows/reusable-beman-create-issue-when-fault.yml@1.7.1 + uses: bemanproject/infra-workflows/.github/workflows/reusable-beman-create-issue-when-fault.yml@b83fb68ccf4644e9185a2e016b7e6dfccc88a06c # ratchet:bemanproject/infra-workflows/.github/workflows/reusable-beman-create-issue-when-fault.yml@1.7.2 diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 5988a13..179eb7f 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -62,7 +62,7 @@ jobs: # your codebase is analyzed, see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages steps: - name: Harden the runner (Audit all outbound calls) - uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2.19.1 + uses: step-security/harden-runner@9ca718d3bf646d6534007c269a635b3e54cadf99 # v2.19.2 with: egress-policy: audit diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index 0aa79fb..f1549b6 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -17,7 +17,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Harden the runner (Audit all outbound calls) - uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2.19.1 + uses: step-security/harden-runner@9ca718d3bf646d6534007c269a635b3e54cadf99 # v2.19.2 with: egress-policy: audit diff --git a/.github/workflows/doxygen-gh-pages.yml b/.github/workflows/doxygen-gh-pages.yml index 2dc9576..ae48a1f 100644 --- a/.github/workflows/doxygen-gh-pages.yml +++ b/.github/workflows/doxygen-gh-pages.yml @@ -16,7 +16,7 @@ jobs: contents: write steps: - name: Harden the runner (Audit all outbound calls) - uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2.19.1 + uses: step-security/harden-runner@9ca718d3bf646d6534007c269a635b3e54cadf99 # v2.19.2 with: egress-policy: audit diff --git a/.github/workflows/ossf-scorecard-analysis.yml b/.github/workflows/ossf-scorecard-analysis.yml index 82c0c38..2f7eb24 100644 --- a/.github/workflows/ossf-scorecard-analysis.yml +++ b/.github/workflows/ossf-scorecard-analysis.yml @@ -22,7 +22,7 @@ jobs: steps: - name: Harden the runner (Audit all outbound calls) - uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2.19.1 + uses: step-security/harden-runner@9ca718d3bf646d6534007c269a635b3e54cadf99 # v2.19.2 with: egress-policy: audit diff --git a/.github/workflows/pre-commit-check.yml b/.github/workflows/pre-commit-check.yml index 89e764c..79d39d2 100644 --- a/.github/workflows/pre-commit-check.yml +++ b/.github/workflows/pre-commit-check.yml @@ -18,4 +18,4 @@ jobs: checks: write issues: write pull-requests: write - uses: bemanproject/infra-workflows/.github/workflows/reusable-beman-pre-commit.yml@4d946e210ce2ee68ccd8607c8acccacf171830c5 # ratchet:bemanproject/infra-workflows/.github/workflows/reusable-beman-pre-commit.yml@1.7.1 + uses: bemanproject/infra-workflows/.github/workflows/reusable-beman-pre-commit.yml@b83fb68ccf4644e9185a2e016b7e6dfccc88a06c # ratchet:bemanproject/infra-workflows/.github/workflows/reusable-beman-pre-commit.yml@1.7.2 diff --git a/.github/workflows/pre-commit-update.yml b/.github/workflows/pre-commit-update.yml index 05d9eed..7202ca8 100644 --- a/.github/workflows/pre-commit-update.yml +++ b/.github/workflows/pre-commit-update.yml @@ -12,7 +12,7 @@ permissions: jobs: auto-update-pre-commit: - uses: bemanproject/infra-workflows/.github/workflows/reusable-beman-update-pre-commit.yml@4d946e210ce2ee68ccd8607c8acccacf171830c5 # ratchet:bemanproject/infra-workflows/.github/workflows/reusable-beman-update-pre-commit.yml@1.7.1 + uses: bemanproject/infra-workflows/.github/workflows/reusable-beman-update-pre-commit.yml@b83fb68ccf4644e9185a2e016b7e6dfccc88a06c # ratchet:bemanproject/infra-workflows/.github/workflows/reusable-beman-update-pre-commit.yml@1.7.2 permissions: checks: write issues: write diff --git a/.github/workflows/test_makefile.yaml b/.github/workflows/test_makefile.yaml index 29b3102..22979c0 100644 --- a/.github/workflows/test_makefile.yaml +++ b/.github/workflows/test_makefile.yaml @@ -23,7 +23,7 @@ jobs: image: ghcr.io/bemanproject/testingcontainers-gcc:14@sha256:f7b898e2deb9b470fa47991c5fd37deb151348c1340921c1bf53a731d263e55f # ratchet:ghcr.io/bemanproject/testingcontainers-gcc:14 steps: - name: Harden the runner (Audit all outbound calls) - uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2.19.1 + uses: step-security/harden-runner@9ca718d3bf646d6534007c269a635b3e54cadf99 # v2.19.2 with: egress-policy: audit