Skip to content

Commit 21a0b25

Browse files
committed
Restrict servers that are allowed during release step.
1 parent 2419897 commit 21a0b25

File tree

1 file changed

+15
-1
lines changed

1 file changed

+15
-1
lines changed

.github/workflows/main.yml

Lines changed: 15 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -158,7 +158,21 @@ jobs:
158158
steps:
159159
- uses: step-security/harden-runner@dd2c410b088af7c0dc8046f3ac9a8f4148492a95 # V1.4.5
160160
with:
161-
egress-policy: audit
161+
egress-policy: block
162+
disable-telemetry: true
163+
allowed-endpoints: >
164+
github.com:443
165+
raw.githubusercontent.com:443
166+
repo.maven.apache.org:443
167+
javadoc.io:443
168+
docs.oracle.com:443
169+
docs.gradle.org:443
170+
plugins.gradle.org:443
171+
services.gradle.org:443
172+
downloads.gradle-dn.com:443
173+
jcenter.bintray.com:443
174+
repository.sonatype.org:443
175+
s01.oss.sonatype.org:443
162176
- uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b # v3.0.2
163177
- uses: actions/setup-java@2c7a4878f5d120bd643426d54ae1209b29cc01a3 # v3.4.1
164178
with:

0 commit comments

Comments
 (0)