Bump install-pinned/uv from aa380d2c49f39e53fe6f5635484bb766098ba8b4 to b7f4803deede8b28e084308f6372bc0243ee13e4 #1415
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Dependency review | |
| on: [pull_request] | |
| permissions: read-all | |
| jobs: | |
| dependency-review: | |
| name: Dependency review | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: step-security/harden-runner@95d9a5deda9de15063e7595e9719c11c38c90ae2 | |
| with: | |
| disable-sudo: true | |
| egress-policy: block | |
| allowed-endpoints: > | |
| api.github.com:443 | |
| api.securityscorecards.dev:443 | |
| github.com:443 | |
| - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 | |
| - uses: actions/dependency-review-action@3c4e3dcb1aa7874d2c16be7d79418e9b7efd6261 | |
| with: | |
| allow-ghsas: GHSA-pq67-6m6q-mj2v # urllib3 |