mirror of
https://github.com/Stirling-Tools/Stirling-PDF.git
synced 2026-09-02 21:03:34 +03:00
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.20.0 to 2.20.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/step-security/harden-runner/releases">step-security/harden-runner's releases</a>.</em></p> <blockquote> <h2>v2.20.1</h2> <h2>What's Changed</h2> <ul> <li>AWS CodeBuild-hosted runner support</li> <li>Implicitly allow single-labeled (internal) domains in block-mode</li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/step-security/harden-runner/compare/v2.20.0...v2.20.1">https://github.com/step-security/harden-runner/compare/v2.20.0...v2.20.1</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/step-security/harden-runner/commit/b09bb98e06d4d774595224525879c09bc6e98c40"><code>b09bb98</code></a> Merge pull request <a href="https://redirect.github.com/step-security/harden-runner/issues/680">#680</a> from step-security/aws-code-build</li> <li><a href="https://github.com/step-security/harden-runner/commit/35cd77bcf669054f67ffd3d2802ee54a4f13b5b6"><code>35cd77b</code></a> docs: document the Global Block List in the features list</li> <li><a href="https://github.com/step-security/harden-runner/commit/bb6dbef4bf53876cd2710acd1d36413620d20fb3"><code>bb6dbef</code></a> chore: rebuild dist with clean dependency install</li> <li><a href="https://github.com/step-security/harden-runner/commit/98f73c5a0d2b2cc518e6fb8d973a0a4dde00ba13"><code>98f73c5</code></a> chore: update eBPF agent to v1.8.14</li> <li><a href="https://github.com/step-security/harden-runner/commit/54193c17a4fa3883977217b9afe20378ebe60b19"><code>54193c1</code></a> Reapply "feat(runners): detect AWS CodeBuild-hosted runners as third-party pr...</li> <li><a href="https://github.com/step-security/harden-runner/commit/d22dd481cea4e96cedde031cfe600c248b592d54"><code>d22dd48</code></a> Revert "fix(self-hosted): flush agent events at job end when deploy-on-self-h...</li> <li><a href="https://github.com/step-security/harden-runner/commit/0ff09412fb572363b483a3c86ffe52fe61d9fd19"><code>0ff0941</code></a> fix(self-hosted): flush agent events at job end when deploy-on-self-hosted-vm...</li> <li><a href="https://github.com/step-security/harden-runner/commit/a3c333d110c8d95f34488a22e0e56742cfb1b14f"><code>a3c333d</code></a> Revert "feat(runners): detect AWS CodeBuild-hosted runners as third-party pro...</li> <li><a href="https://github.com/step-security/harden-runner/commit/bf94c00d6bba2ae7c4a479b86653039811569968"><code>bf94c00</code></a> feat(runners): detect AWS CodeBuild-hosted runners as third-party provider</li> <li><a href="https://github.com/step-security/harden-runner/commit/514522c5e449f9e28fc901f770e08a573d413e67"><code>514522c</code></a> fix(self-hosted): resolve runner user when USER env var is unset</li> <li>See full diff in <a href="https://github.com/step-security/harden-runner/compare/bf7454d06d71f1098171f2acdf0cd4708d7b5920...b09bb98e06d4d774595224525879c09bc6e98c40">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
68 lines
2.0 KiB
YAML
68 lines
2.0 KiB
YAML
name: _runner-pick
|
|
|
|
# Tiny reusable workflow that classifies the trigger as either a "fork PR
|
|
# from an untrusted contributor" or a "trusted commit" so downstream jobs
|
|
# can trust-gate (skip secret-dependent jobs on forks) without each one
|
|
# duplicating the gate expression.
|
|
#
|
|
# Caller pattern:
|
|
#
|
|
# jobs:
|
|
# pick:
|
|
# uses: ./.github/workflows/_runner-pick.yml
|
|
#
|
|
# real-work:
|
|
# needs: pick
|
|
# if: needs.pick.outputs.is_fork != 'true'
|
|
# steps: [...]
|
|
#
|
|
# Outputs:
|
|
# is_fork: "true" when the trigger is a pull_request from a fork or an
|
|
# untrusted author_association, "false" otherwise.
|
|
|
|
on:
|
|
workflow_call:
|
|
outputs:
|
|
is_fork:
|
|
description: '"true" if the trigger is an untrusted fork PR.'
|
|
value: ${{ jobs.pick.outputs.is_fork }}
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
pick:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 1
|
|
outputs:
|
|
is_fork: ${{ steps.decide.outputs.is_fork }}
|
|
steps:
|
|
- name: Harden the runner (Audit all outbound calls)
|
|
uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
|
|
with:
|
|
egress-policy: audit
|
|
|
|
- name: Classify the trigger
|
|
id: decide
|
|
env:
|
|
PR_NUMBER: ${{ github.event.pull_request.number }}
|
|
HEAD_REPO_FORK: ${{ github.event.pull_request.head.repo.fork }}
|
|
AUTHOR_ASSOC: ${{ github.event.pull_request.author_association }}
|
|
run: |
|
|
set -eu
|
|
|
|
if [ -z "${PR_NUMBER:-}" ]; then
|
|
# Not a pull_request event at all (push, schedule, workflow_dispatch,
|
|
# workflow_call from a non-PR trigger) -> trusted by default.
|
|
is_fork=false
|
|
elif [ "${HEAD_REPO_FORK}" = "true" ]; then
|
|
is_fork=true
|
|
else
|
|
case "${AUTHOR_ASSOC}" in
|
|
OWNER|MEMBER|COLLABORATOR) is_fork=false ;;
|
|
*) is_fork=true ;;
|
|
esac
|
|
fi
|
|
|
|
echo "is_fork=${is_fork}" >> "$GITHUB_OUTPUT"
|