From ae4cda6426bf87a0417293a1d521ed1e0e8f4fbc Mon Sep 17 00:00:00 2001 From: "stepsecurity-app[bot]" <188008098+stepsecurity-app[bot]@users.noreply.github.com> Date: Thu, 8 Oct 2026 16:27:01 +0000 Subject: [PATCH] [StepSecurity] Apply security best practices Signed-off-by: StepSecurity Bot --- .github/workflows/test-sticky-tool-cache.yml | 23 ++++++++++++++++---- 1 file changed, 19 insertions(+), 4 deletions(-) diff --git a/.github/workflows/test-sticky-tool-cache.yml b/.github/workflows/test-sticky-tool-cache.yml index e055696..cd31666 100644 --- a/.github/workflows/test-sticky-tool-cache.yml +++ b/.github/workflows/test-sticky-tool-cache.yml @@ -22,7 +22,12 @@ jobs: image: windows25-full-x64 runs-on: runs-on=${{ github.run_id }}/env=bootstrap/cpu=2/family=m7/image=${{ matrix.image }}/sticky=tool-cache-${{ github.run_id }}-${{ github.run_attempt }}-${{ matrix.id }}:20gb steps: - - uses: actions/checkout@v7 + - name: Harden the runner (Audit all outbound calls) + uses: step-security/harden-runner@v2 + with: + egress-policy: audit + + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Seed image-only tool cache content on Linux if: runner.os == 'Linux' shell: bash @@ -58,7 +63,7 @@ jobs: if ($env:CACHE_HIT -ne "false") { throw "cold cache unexpectedly reported a hit" } if (Test-Path -LiteralPath (Join-Path $env:RUNNER_TOOL_CACHE "image-only")) { throw "image tool cache was inherited" } if (Get-ChildItem -Force -LiteralPath $env:RUNNER_TOOL_CACHE | Select-Object -First 1) { throw "cold sticky tool cache is not empty" } - - uses: actions/setup-go@v7 + - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version: '1.25.1' cache: false @@ -87,6 +92,11 @@ jobs: needs: cold runs-on: ubuntu-slim steps: + - name: Harden the runner (Audit all outbound calls) + uses: step-security/harden-runner@v2 + with: + egress-policy: audit + - name: Wait for the cold snapshot to become selectable run: sleep 120 @@ -102,7 +112,12 @@ jobs: image: windows25-full-x64 runs-on: runs-on=${{ github.run_id }}/env=bootstrap/cpu=2/family=m7/image=${{ matrix.image }}/sticky=tool-cache-${{ github.run_id }}-${{ github.run_attempt }}-${{ matrix.id }}:20gb steps: - - uses: actions/checkout@v7 + - name: Harden the runner (Audit all outbound calls) + uses: step-security/harden-runner@v2 + with: + egress-policy: audit + + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Seed fresh image-only tool cache content on Linux if: runner.os == 'Linux' shell: bash @@ -138,7 +153,7 @@ jobs: if ($env:CACHE_HIT -ne "true") { throw "restored cache did not report a hit" } if (Test-Path -LiteralPath (Join-Path $env:RUNNER_TOOL_CACHE "image-only")) { throw "fresh image tool cache was inherited" } if (-not (Get-ChildItem -Force -LiteralPath $env:RUNNER_TOOL_CACHE -Filter ".runs-on-tool-cache-e2e" -Recurse | Select-Object -First 1)) { throw "restored toolchain marker is missing" } - - uses: actions/setup-go@v7 + - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version: '1.25.1' cache: false