1515 runs-on : ubuntu-latest
1616
1717 steps :
18+ - name : Harden the runner (Audit all outbound calls)
19+ uses : step-security/harden-runner@v2
20+ with :
21+ egress-policy : audit
22+
1823 - name : Clone repository
19- uses : actions/checkout@v7
24+ uses : actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
2025 - name : Run shellcheck
2126 uses : step-security/action-shellcheck@v2
2227
3439 channel : main
3540
3641 steps :
42+ - name : Harden the runner (Audit all outbound calls)
43+ uses : step-security/harden-runner@v2
44+ with :
45+ egress-policy : audit
46+
3747 - name : Clone repository
38- uses : actions/checkout@v7
48+ uses : actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
3949 - id : flutter-action
4050 uses : ./
4151 with :
7484 operating-system : ${{ github.actor == 'dependabot[bot]' && fromJSON('["ubuntu-latest"]') || fromJSON('["ubuntu-latest", "windows-latest", "macos-latest"]') }}
7585
7686 steps :
87+ - name : Harden the runner (Audit all outbound calls)
88+ uses : step-security/harden-runner@v2
89+ with :
90+ egress-policy : audit
91+
7792 - name : Clone repository
78- uses : actions/checkout@v7
93+ uses : actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
7994 - uses : ./
8095 with :
8196 channel : stable
@@ -94,8 +109,13 @@ jobs:
94109 operating-system : ${{ github.actor == 'dependabot[bot]' && fromJSON('["ubuntu-latest"]') || fromJSON('["ubuntu-latest"]') }}
95110
96111 steps :
112+ - name : Harden the runner (Audit all outbound calls)
113+ uses : step-security/harden-runner@v2
114+ with :
115+ egress-policy : audit
116+
97117 - name : Clone repository
98- uses : actions/checkout@v7
118+ uses : actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
99119 - uses : ./
100120 with :
101121 channel : stable
@@ -115,8 +135,13 @@ jobs:
115135 operating-system : ${{ github.actor == 'dependabot[bot]' && fromJSON('["ubuntu-latest"]') || fromJSON('["ubuntu-latest", "macos-latest"]') }}
116136
117137 steps :
138+ - name : Harden the runner (Audit all outbound calls)
139+ uses : step-security/harden-runner@v2
140+ with :
141+ egress-policy : audit
142+
118143 - name : Clone repository
119- uses : actions/checkout@v7
144+ uses : actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
120145 - id : flutter-action
121146 uses : ./
122147 with :
@@ -143,8 +168,13 @@ jobs:
143168 # Test mode uses hardcoded Flutter release manifests from test/ directory.
144169
145170 steps :
171+ - name : Harden the runner (Audit all outbound calls)
172+ uses : step-security/harden-runner@v2
173+ with :
174+ egress-policy : audit
175+
146176 - name : Clone repository
147- uses : actions/checkout@v7
177+ uses : actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
148178 - run : ./setup.sh -t -p -f test/pubspec.yaml | grep '3.3.10'
149179 shell : bash
150180 - run : ./setup.sh -t -p | grep 'stable'
@@ -241,8 +271,13 @@ jobs:
241271 # Test mode uses hardcoded Flutter release manifests from test/ directory.
242272
243273 steps :
274+ - name : Harden the runner (Audit all outbound calls)
275+ uses : step-security/harden-runner@v2
276+ with :
277+ egress-policy : audit
278+
244279 - name : Clone repository
245- uses : actions/checkout@v7
280+ uses : actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
246281 - run : ./setup.sh -t -p -f test/pubspec.yaml | grep '3.3.10'
247282 shell : bash
248283 - run : ./setup.sh -t -p | grep 'stable'
0 commit comments