Skip to content

Commit e0db281

Browse files
authored
Merge branch 'main' into feature/DEF-3580-dependency-review-v3
2 parents d28186a + d219881 commit e0db281

10 files changed

+11
-166
lines changed

.github/workflows/actions-codeql.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ jobs:
2424

2525
steps:
2626
- name: Harden Runner
27-
uses: step-security/harden-runner@c95a14d0e5bab51a9f56296a4eb0e416910cd350 # v2.10.3
27+
uses: step-security/harden-runner@4d991eb9b905ef189e4c376166672c3f2f230481 # v2.11.0
2828
with:
2929
egress-policy: audit
3030

.github/workflows/dependency-review-v2.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -57,7 +57,7 @@ jobs:
5757

5858
steps:
5959
- name: Harden Runner
60-
uses: step-security/harden-runner@c95a14d0e5bab51a9f56296a4eb0e416910cd350 # v2.10.3
60+
uses: step-security/harden-runner@4d991eb9b905ef189e4c376166672c3f2f230481 # v2.11.0
6161
with:
6262
egress-policy: audit
6363

@@ -120,7 +120,7 @@ jobs:
120120
core.setFailure(`Could not determine configuration for inputs: ${inputs}`)
121121
122122
- name: Scan
123-
uses: actions/dependency-review-action@72eb03d02c7872a771aacd928f3123ac62ad6d3a # v4.3.3
123+
uses: actions/dependency-review-action@72eb03d02c7872a771aacd928f3123ac62ad6d3a # v4.3.3 Can't update past this version because https://github.com/actions/dependency-review-action/issues/907
124124
with:
125125
comment-summary-in-pr: ${{ inputs.comment-summary-in-pr }}
126126
fail-on-severity: ${{ inputs.fail-on-severity }}

.github/workflows/dependency-review.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -63,7 +63,7 @@ jobs:
6363
pull-requests: write
6464
steps:
6565
- name: Harden Runner
66-
uses: step-security/harden-runner@c95a14d0e5bab51a9f56296a4eb0e416910cd350 # v2.10.3
66+
uses: step-security/harden-runner@4d991eb9b905ef189e4c376166672c3f2f230481 # v2.11.0
6767
with:
6868
egress-policy: audit
6969

.github/workflows/java-maven-openjdk-codeql.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -45,7 +45,7 @@ jobs:
4545
# Allow calling Git on a working copy owned by another user than the current one.
4646
# see: https://github.blog/2022-04-12-git-security-vulnerability-announced/
4747
- name: Harden Runner
48-
uses: step-security/harden-runner@c95a14d0e5bab51a9f56296a4eb0e416910cd350 # v2.10.3
48+
uses: step-security/harden-runner@4d991eb9b905ef189e4c376166672c3f2f230481 # v2.11.0
4949
with:
5050
egress-policy: audit
5151

@@ -64,7 +64,7 @@ jobs:
6464
languages: java
6565

6666
- name: Cache maven dependencies
67-
uses: actions/[email protected].0
67+
uses: actions/[email protected].3
6868
with:
6969
path: ~/.m2
7070
key: ${{ runner.os }}-maven-${{ hashFiles('**/pom.xml') }}

.github/workflows/java-maven-openjdk-dependency-submission.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -50,15 +50,15 @@ jobs:
5050

5151
steps:
5252
- name: Harden Runner
53-
uses: step-security/harden-runner@c95a14d0e5bab51a9f56296a4eb0e416910cd350 # v2.10.3
53+
uses: step-security/harden-runner@4d991eb9b905ef189e4c376166672c3f2f230481 # v2.11.0
5454
with:
5555
egress-policy: audit
5656

5757
- name: Checkout repository
5858
uses: actions/[email protected]
5959

6060
- name: Cache maven dependencies
61-
uses: actions/[email protected].0
61+
uses: actions/[email protected].3
6262
with:
6363
path: ~/.m2
6464
key: ${{ runner.os }}-maven-${{ hashFiles('**/pom.xml') }}

.github/workflows/java-maven-openjdk11-codeql.yml

Lines changed: 0 additions & 27 deletions
This file was deleted.

.github/workflows/java-maven-openjdk11-dependency-submission.yml

Lines changed: 0 additions & 28 deletions
This file was deleted.

.github/workflows/scorecard.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ jobs:
3131

3232
steps:
3333
- name: Harden Runner
34-
uses: step-security/harden-runner@c95a14d0e5bab51a9f56296a4eb0e416910cd350 # v2.10.3
34+
uses: step-security/harden-runner@4d991eb9b905ef189e4c376166672c3f2f230481 # v2.11.0
3535
with:
3636
disable-sudo: true
3737
egress-policy: audit
@@ -53,7 +53,7 @@ jobs:
5353
persist-credentials: false
5454

5555
- name: "Run analysis"
56-
uses: ossf/scorecard-action@62b2cac7ed8198b15735ed49ab1e5cf35480ba46 # v2.4.0
56+
uses: ossf/scorecard-action@f49aabe0b5af0936a0987cfb85d86b75731b0186 # v2.4.1
5757
with:
5858
results_file: results.sarif
5959
results_format: sarif
@@ -75,7 +75,7 @@ jobs:
7575
# Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
7676
# format to the repository Actions tab.
7777
- name: "Upload artifact"
78-
uses: actions/[email protected].0
78+
uses: actions/[email protected].2
7979
with:
8080
name: SARIF file
8181
path: results.sarif

CODEOWNERS

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,8 +4,6 @@ audit-renovate-config/** @coveo/dev-tooling @coveo/r-d-security-defence @coveo/c
44
.github/workflows/actions-codeql.yml @coveo/r-d-security-defence
55
.github/workflows/dependency-review.yml @coveo/r-d-security-defence
66
.github/workflows/dependency-review-v2.yml @coveo/r-d-security-defence
7-
.github/workflows/java-maven-openjdk11-codeql.yml @coveo/r-d-security-defence
8-
.github/workflows/java-maven-openjdk11-dependency-submission.yml @coveo/r-d-security-defence
97
.github/workflows/java-maven-openjdk-codeql.yml @coveo/r-d-security-defence
108
.github/workflows/java-maven-openjdk-dependency-review.yml @coveo/r-d-security-defence
119
.github/workflows/java-maven-openjdk-dependency-submission.yml @coveo/r-d-security-defence

audit-renovate-config/action.yaml

Lines changed: 0 additions & 98 deletions
This file was deleted.

0 commit comments

Comments
 (0)