Skip to content

Bump step-security/harden-runner from 2.13.3 to 2.14.0 in the actions group #2377

Bump step-security/harden-runner from 2.13.3 to 2.14.0 in the actions group

Bump step-security/harden-runner from 2.13.3 to 2.14.0 in the actions group #2377

Workflow file for this run

name: 'Dependency Review'
on:
pull_request:
branches:
- master
permissions: {}
jobs:
dependency-review:
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- name: Harden Runner
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
with:
disable-sudo: true
egress-policy: block
allowed-endpoints: >
api.github.com:443
github.com:443
api.securityscorecards.dev:443
api.deps.dev:443
- name: 'Checkout Repository'
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
persist-credentials: false
- name: 'Dependency Review'
uses: actions/dependency-review-action@3c4e3dcb1aa7874d2c16be7d79418e9b7efd6261 # v4.8.2