Skip to content

Commit cc60936

Browse files
authored
Merge pull request #50 from step-security-bot/stepsecurity_remediation_1727866218
[StepSecurity] Apply security best practices
2 parents 307593a + 2643764 commit cc60936

File tree

2 files changed

+16
-5
lines changed

2 files changed

+16
-5
lines changed

.github/dependabot.yml

+11
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
version: 2
2+
updates:
3+
- package-ecosystem: github-actions
4+
directory: /
5+
schedule:
6+
interval: daily
7+
8+
- package-ecosystem: gomod
9+
directory: /
10+
schedule:
11+
interval: daily

.github/workflows/release-builder.yml

+5-5
Original file line numberDiff line numberDiff line change
@@ -19,18 +19,18 @@ jobs:
1919

2020
steps:
2121
- name: Checkout code
22-
uses: actions/checkout@v4
22+
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
2323

2424
- name: Set Release Version
2525
run: echo "RELEASE_VERSION=$RELEASE_VERSION" >> $GITHUB_ENV
2626

2727
- name: Set up Go
28-
uses: actions/setup-go@v5
28+
uses: actions/setup-go@0a12ed9d6a96ab950c8f026ed9f722fe0da7ef32 # v5.0.2
2929
with:
3030
go-version: '1.22.4'
3131

3232
- name: Install Cosign
33-
uses: sigstore/[email protected]
33+
uses: sigstore/cosign-installer@4959ce089c160fddf62f7b42464195ba1a56d382 # v3.6.0
3434
with:
3535
cosign-release: 'v2.4.0'
3636

@@ -61,11 +61,11 @@ jobs:
6161
--output-certificate="release/kubectl-nginx_supportpkg_${VERSION}_checksums.txt.pem" -y
6262
6363
- name: Upload release binaries
64-
uses: alexellis/[email protected]
64+
uses: alexellis/upload-assets@13926a61cdb2cb35f5fdef1c06b8b591523236d3 # 0.4.1
6565
env:
6666
GITHUB_TOKEN: ${{ github.token }}
6767
with:
6868
asset_paths: '["./release/*.gz", "./release/*.txt", "./release/*.sig", "./release/*.pem"]'
6969

7070
- name: Update new version in krew-index
71-
uses: rajatjindal/[email protected]
71+
uses: rajatjindal/krew-release-bot@df3eb197549e3568be8b4767eec31c5e8e8e6ad8 # v0.0.46

0 commit comments

Comments
 (0)