From c1a7c6bd829eea100def6e58a46f0aac314497cd Mon Sep 17 00:00:00 2001 From: StepSecurity Bot Date: Fri, 24 Jan 2025 18:42:25 +0000 Subject: [PATCH] [StepSecurity] ci: Harden GitHub Actions Signed-off-by: StepSecurity Bot --- .github/workflows/createNewCodeSandBoxDemo.yml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/.github/workflows/createNewCodeSandBoxDemo.yml b/.github/workflows/createNewCodeSandBoxDemo.yml index d5b1387..d58f621 100644 --- a/.github/workflows/createNewCodeSandBoxDemo.yml +++ b/.github/workflows/createNewCodeSandBoxDemo.yml @@ -6,6 +6,11 @@ jobs: create-new-demo: runs-on: ubuntu-latest steps: + - name: Harden Runner + uses: step-security/harden-runner@v2 + with: + egress-policy: audit + - name: Setup Ruby in runner uses: ruby/setup-ruby@ee26e27437bde475b19a6bf8cb73c9fa658876a2 with: