Skip to content

Commit 2da9582

Browse files
committed
chore(cicd): update Harden Github Actions policy + remove unused ZAP artifact
1 parent 8152e3d commit 2da9582

File tree

1 file changed

+19
-7
lines changed

1 file changed

+19
-7
lines changed

.github/workflows/nodejs.yml

Lines changed: 19 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -146,7 +146,25 @@ jobs:
146146
- name: Harden GitHub Actions Runner
147147
uses: step-security/harden-runner@dd5681a7d0c66fb362664d618ef4a90d656f6516
148148
with:
149-
egress-policy: audit
149+
egress-policy: block
150+
allowed-endpoints: >
151+
api.github.com:443
152+
auth.docker.io:443
153+
bit.ly:443
154+
content-signature-2.cdn.mozilla.net:443
155+
firefox.settings.services.mozilla.com:443
156+
github.com:443
157+
news.zaproxy.org:443
158+
objects.githubusercontent.com:443
159+
pipelines.actions.githubusercontent.com:443
160+
production.cloudflare.docker.com:443
161+
raw.githubusercontent.com:443
162+
registry-1.docker.io:443
163+
registry.npmjs.org:443
164+
shavar.services.mozilla.com:443
165+
snyk.io:443
166+
tel.zaproxy.org:443
167+
tracking-protection.cdn.mozilla.net:443
150168
151169
- name: Checkout
152170
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b # tag=v3.0.2
@@ -174,12 +192,6 @@ jobs:
174192
with:
175193
target: http://localhost:3000
176194

177-
- name: Save the ZAP reports
178-
uses: actions/upload-artifact@3cea5372237819ed00197afe530f5a7ea3e805c8 # tag=v3.1.0
179-
with:
180-
name: zap-reports
181-
path: report_*.*
182-
183195
# -- PRE-RELEASE ------------------------------------------------------------
184196
pre-release:
185197
name: Prepare Release

0 commit comments

Comments
 (0)