Skip to content

Commit 8ca2b8b

Browse files
Release v2.5.1 (#332)
1 parent 9768986 commit 8ca2b8b

File tree

8 files changed

+9
-7
lines changed

8 files changed

+9
-7
lines changed

.github/workflows/canary.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,7 @@ jobs:
2424
steps:
2525
- uses: step-security/harden-runner@cba0d00b1fc9a034e1e642ea0f1103c282990604 # v1
2626
with:
27+
egress-policy: audit
2728
allowed-endpoints:
2829
api.github.com:443
2930
github.com:443

.github/workflows/release.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -27,6 +27,7 @@ jobs:
2727
steps:
2828
- uses: step-security/harden-runner@cba0d00b1fc9a034e1e642ea0f1103c282990604
2929
with:
30+
egress-policy: audit
3031
allowed-endpoints:
3132
api.github.com:443
3233
github.com:443

.github/workflows/test.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ jobs:
1919
uses: step-security/harden-runner@cba0d00b1fc9a034e1e642ea0f1103c282990604 # v2.5.0
2020
with:
2121
disable-sudo: true
22-
egress-policy: block
22+
egress-policy: audit
2323
allowed-endpoints: >
2424
api.github.com:443
2525
codecov.io:443

dist/pre/index.js

Lines changed: 2 additions & 2 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

dist/pre/index.js.map

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"name": "step-security-harden-runner",
3-
"version": "2.4.1",
3+
"version": "2.5.1",
44
"description": "Security agent for GitHub-hosted runner: block egress traffic & detect code overwrite to prevent breaches",
55
"main": "index.js",
66
"scripts": {

src/checksum.ts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ export function verifyChecksum(downloadPath: string) {
1010
.digest("hex"); // checksum of downloaded file
1111

1212
const expectedChecksum: string =
13-
"79cc2df62f6eba9ab4ceadbbdfca4d20ef5b14e1439a98eaa559142b8dd61aac"; // checksum for v0.13.4
13+
"ceb925c78e5c79af4f344f08f59bbdcf3376d20d15930a315f9b24b6c4d0328a"; // checksum for v0.13.5
1414

1515
if (checksum !== expectedChecksum) {
1616
core.setFailed(

src/setup.ts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -168,7 +168,7 @@ import { isArcRunner, sendAllowedEndpoints } from "./arc-runner";
168168
let auth = `token ${token}`;
169169

170170
const downloadPath: string = await tc.downloadTool(
171-
"https://github.com/step-security/agent/releases/download/v0.13.4/agent_0.13.4_linux_amd64.tar.gz",
171+
"https://github.com/step-security/agent/releases/download/v0.13.5/agent_0.13.5_linux_amd64.tar.gz",
172172
undefined,
173173
auth
174174
);

0 commit comments

Comments
 (0)