neilnaveen
|
1479e696c3
|
Added permissions for GitHub actions (#3804)
- Included permissions for the action. https://github.com/ossf/scorecard/blob/main/docs/checks.md#token-permissions
https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions
https://docs.github.com/en/actions/using-jobs/assigning-permissions-to-jobs
[Keeping your GitHub Actions and workflows secure Part 1: Preventing pwn requests](https://securitylab.github.com/research/github-actions-preventing-pwn-requests/)
Restrict the GitHub token permissions only to the required ones; this way, even if the attackers will succeed in compromising your workflow, they won’t be able to do much.
Signed-off-by: neilnaveen <42328488+neilnaveen@users.noreply.github.com>
|
2022-04-08 15:44:43 +02:00 |
|
dependabot[bot]
|
ffb21e9d05
|
Bump actions/cache from 2 to 3 (#3780)
Bumps [actions/cache](https://github.com/actions/cache) from 2 to 3.
- [Release notes](https://github.com/actions/cache/releases)
- [Commits](https://github.com/actions/cache/compare/v2...v3)
---
updated-dependencies:
- dependency-name: actions/cache
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
|
2022-03-28 18:02:07 +02:00 |
|
dependabot[bot]
|
b71f8bf6ca
|
Bump actions/checkout from 2 to 3
Bumps [actions/checkout](https://github.com/actions/checkout) from 2 to 3.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v2...v3)
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2022-03-07 08:38:57 +01:00 |
|
dependabot[bot]
|
1ff8fedbfc
|
Bump actions/setup-node from 2.5.1 to 3
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 2.5.1 to 3.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](https://github.com/actions/setup-node/compare/v2.5.1...v3)
---
updated-dependencies:
- dependency-name: actions/setup-node
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2022-02-28 04:22:19 +00:00 |
|
squidfunk
|
9655c3a924
|
Updated dependencies and bumped copyright year
|
2022-01-10 09:59:00 +01:00 |
|
dependabot[bot]
|
5fa155d7fe
|
Bump actions/setup-node from 2.5.0 to 2.5.1
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 2.5.0 to 2.5.1.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](https://github.com/actions/setup-node/compare/v2.5.0...v2.5.1)
---
updated-dependencies:
- dependency-name: actions/setup-node
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2022-01-05 17:02:08 +01:00 |
|
dependabot[bot]
|
cdaf0305b5
|
Bump actions/setup-node from 1 to 2.5.0
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 1 to 2.5.0.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](https://github.com/actions/setup-node/compare/v1...v2.5.0)
---
updated-dependencies:
- dependency-name: actions/setup-node
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2021-12-12 11:13:07 +01:00 |
|
squidfunk
|
b33aba3da6
|
Updated dependencies
|
2021-08-30 09:11:43 +02:00 |
|
squidfunk
|
0bbe0f2f4f
|
Switched to Node 14
|
2021-02-22 18:25:12 +01:00 |
|
squidfunk
|
08e8525689
|
Updated copyright year
|
2021-02-14 16:54:27 +01:00 |
|
squidfunk
|
9e34a3d23e
|
Updated dependencies
|
2020-11-24 18:49:17 +01:00 |
|
squidfunk
|
c563ca52cd
|
Formatting
|
2020-11-22 12:04:31 +01:00 |
|
squidfunk
|
753477caaf
|
Split up GitHub Actions workflows
|
2020-11-22 12:01:43 +01:00 |
|