Skip to content

Bump step-security/harden-runner from 2.7.0 to 2.11.0 #6

Bump step-security/harden-runner from 2.7.0 to 2.11.0

Bump step-security/harden-runner from 2.7.0 to 2.11.0 #6

name: dependency-review
on:
pull_request:
permissions:
contents: none
pull-requests: none
jobs:
dependency-review:
runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: write
steps:
- name: 🔒 harden runner
uses: step-security/harden-runner@4d991eb9b905ef189e4c376166672c3f2f230481 # v2.11.0
with:
egress-policy: audit
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
- name: 🔂 dependency review
uses: actions/dependency-review-action@5a2ce3f5b92ee19cbb1541a4984c76d921601d7c # v4.3.4
with:
deny-licenses: AGPL-3.0
fail-on-severity: moderate
comment-summary-in-pr: true