fix(ci): pin actions to their commit sha
Floating tags let a compromised or force pushed release change what the workflows execute. Pinning the actions to a commit sha and restricting the default token to read access limits the blast radius of a supply chain attack. The outdated ansible-lint and markdownlint-cli2 versions are raised along with the pinning. The ansible-lint run installs the collections of the molecule scenario, because the scenario is linted as well and depends on community.docker beside the community.general requirement of the role. Co-authored-by: Copilot <copilot@github.com>
This commit is contained in:
@@ -6,6 +6,9 @@ on:
|
||||
- '**'
|
||||
workflow_dispatch: {}
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
release:
|
||||
name: Release Ansible Role
|
||||
|
||||
Reference in New Issue
Block a user