From 868029016aafe1154ea37078f4438f4eac005e7f Mon Sep 17 00:00:00 2001 From: shubham-stepsecurity Date: Tue, 12 Nov 2024 13:44:50 +0530 Subject: [PATCH 1/3] Create Sample_test_workflow.yml --- .github/workflows/Sample_test_workflow.yml | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) create mode 100644 .github/workflows/Sample_test_workflow.yml diff --git a/.github/workflows/Sample_test_workflow.yml b/.github/workflows/Sample_test_workflow.yml new file mode 100644 index 0000000..e673dad --- /dev/null +++ b/.github/workflows/Sample_test_workflow.yml @@ -0,0 +1,22 @@ +name: Int Harden Runner + +on: [pull_request, workflow_dispatch] + +jobs: + harden-and-basic-tasks: + runs-on: ubuntu-latest + steps: + - name: Checkout Repository + uses: actions/checkout@v3 + + - name: Run Step Security Harden Runner + uses: step-security/harden-runner@int + with: + egress-policy: audit + + - name: List Files in Repository + run: ls -al + + - name: Make API Call with Curl + run: | + curl -X GET "https://google.com" -H "Content-Type: application/json" From 1b6de57ee8c19fff22406f65078acf884258d43a Mon Sep 17 00:00:00 2001 From: shubham-stepsecurity Date: Thu, 14 Nov 2024 21:05:44 +0530 Subject: [PATCH 2/3] Rename Sample_test_workflow.yml to test_workflow.yml --- .github/workflows/{Sample_test_workflow.yml => test_workflow.yml} | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename .github/workflows/{Sample_test_workflow.yml => test_workflow.yml} (100%) diff --git a/.github/workflows/Sample_test_workflow.yml b/.github/workflows/test_workflow.yml similarity index 100% rename from .github/workflows/Sample_test_workflow.yml rename to .github/workflows/test_workflow.yml From 1eba5dfd84fedbf878ffc63c27f07aa3a7977a1a Mon Sep 17 00:00:00 2001 From: shubham-stepsecurity Date: Wed, 20 Nov 2024 21:12:54 +0530 Subject: [PATCH 3/3] Update scorecards.yml --- .github/workflows/scorecards.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/scorecards.yml b/.github/workflows/scorecards.yml index 479aa0f..a6cd43f 100644 --- a/.github/workflows/scorecards.yml +++ b/.github/workflows/scorecards.yml @@ -13,6 +13,7 @@ on: - cron: '20 7 * * 2' push: branches: ["main"] + pull_request: # Declare default permissions as read only. permissions: read-all