We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent f843b6b commit e7dde9bCopy full SHA for e7dde9b
.github/workflows/dependabot-auto-merge.yml
@@ -13,9 +13,14 @@ jobs:
13
runs-on: ubuntu-latest
14
if: ${{ github.actor == 'dependabot[bot]' }}
15
steps:
16
+ - name: Harden the runner (Audit all outbound calls)
17
+ uses: step-security/harden-runner@ec9f2d5744a09debf3a187a3f4f675c53b671911 # v2.13.0
18
+ with:
19
+ egress-policy: audit
20
+
21
- name: Dependabot metadata
22
id: metadata
- uses: dependabot/fetch-metadata@v2.4.0
23
+ uses: dependabot/fetch-metadata@08eff52bf64351f401fb50d4972fa95b9f2c2d1b # v2.4.0
24
with:
25
github-token: "${{ secrets.GITHUB_TOKEN }}"
26
0 commit comments