Skip to content

ci: Harden GitHub Actions workflows#19

Open
gcl-sekoia wants to merge 4 commits into
SEKOIA-IO:masterfrom
gcl-sekoia:gha-security/harden
Open

ci: Harden GitHub Actions workflows#19
gcl-sekoia wants to merge 4 commits into
SEKOIA-IO:masterfrom
gcl-sekoia:gha-security/harden

Conversation

@gcl-sekoia

@gcl-sekoia gcl-sekoia commented Mar 20, 2026

Copy link
Copy Markdown

Summary

  • Configure Dependabot for GitHub Actions (weekly, 14-day cooldown, grouped version updates)
  • Pin actions to commit SHAs (14-day minimum age)
  • Least-privilege permissions (deny-all at workflow level, minimal job-level grants)
  • Fix actionlint findings

Edit: the workflow ran here, all looks alright to me:
https://github.com/SEKOIA-IO/SEKOIA.IO-for-Splunk/actions/runs/23350576781

@gcl-sekoia gcl-sekoia marked this pull request as ready for review March 20, 2026 16:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant