Skip to content

Commit faf8494

Browse files
authored
Merge pull request #420 from ivpn/fix/ci-hardening
Update github actions
2 parents 128fbb6 + 2116303 commit faf8494

3 files changed

Lines changed: 16 additions & 10 deletions

File tree

.github/workflows/build.yml

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -5,21 +5,24 @@ on:
55
branches: [ "main", "develop" ]
66
pull_request:
77

8+
permissions:
9+
contents: read
10+
811
jobs:
912
build:
1013
runs-on: ubuntu-latest
1114

1215
steps:
13-
- uses: actions/checkout@v3
16+
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
1417

1518
- name: Validate Gradle Wrapper
16-
uses: gradle/wrapper-validation-action@v1
19+
uses: gradle/wrapper-validation-action@56b90f209b02bf6d1deae490e9ef18b21a389cd4 # v1
1720

1821
- name: Checkout submodules
1922
run: git submodule update --init --recursive
2023

2124
- name: Set up NDK
22-
uses: nttld/setup-ndk@v1
25+
uses: nttld/setup-ndk@ed92fe6cadad69be94a966a7ee3271275e62f779 # v1
2326
with:
2427
ndk-version: r25b
2528

@@ -31,7 +34,7 @@ jobs:
3134
xsltproc doxygen graphviz python3-yaml valgrind
3235
3336
- name: Set up JDK 17
34-
uses: actions/setup-java@v3
37+
uses: actions/setup-java@17f84c3641ba7b8f6deff6309fc4c864478f5d62 # v3
3538
with:
3639
java-version: '17'
3740
distribution: 'temurin'

.github/workflows/codeql.yml

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,9 @@ on:
77
schedule:
88
- cron: '19 1 * * 3'
99

10+
permissions:
11+
contents: read
12+
1013
jobs:
1114
analyze_java:
1215
name: Analyze Java
@@ -22,21 +25,21 @@ jobs:
2225

2326
steps:
2427
- name: Checkout repository
25-
uses: actions/checkout@v3
28+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
2629

2730
- name: Validate Gradle Wrapper
28-
uses: gradle/wrapper-validation-action@v1
31+
uses: gradle/wrapper-validation-action@56b90f209b02bf6d1deae490e9ef18b21a389cd4 # v1
2932

3033
- name: Initialize CodeQL
31-
uses: github/codeql-action/init@v2
34+
uses: github/codeql-action/init@8dca8a82e2fa1a2c8908956f711300f9c4a4f4f6 # v2
3235
with:
3336
languages: java
3437

3538
- name: Checkout submodules
3639
run: git submodule update --init --recursive
3740

3841
- name: Set up JDK 17
39-
uses: actions/setup-java@v3
42+
uses: actions/setup-java@17f84c3641ba7b8f6deff6309fc4c864478f5d62 # v3
4043
with:
4144
java-version: '17'
4245
distribution: 'temurin'
@@ -49,6 +52,6 @@ jobs:
4952
run: ./gradlew :core:assemble -x validateSigningProductionRelease
5053

5154
- name: Perform CodeQL Analysis
52-
uses: github/codeql-action/analyze@v2
55+
uses: github/codeql-action/analyze@8dca8a82e2fa1a2c8908956f711300f9c4a4f4f6 # v2
5356
with:
5457
category: "/language:Java"

.github/workflows/stale.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ jobs:
1818
pull-requests: write
1919

2020
steps:
21-
- uses: actions/stale@v5
21+
- uses: actions/stale@f7176fd3007623b69d27091f9b9d4ab7995f0a06 # v5
2222
with:
2323
repo-token: ${{ secrets.GITHUB_TOKEN }}
2424
stale-issue-message: 'This issue is stale because it has been open 60 days with no activity.'

0 commit comments

Comments
 (0)