fix(ci): pin actions to their commit sha
Floating tags let a compromised or force pushed release change what the workflows execute. Pinning the actions to a commit sha and restricting the default token to read access limits the blast radius of a supply chain attack. The outdated ansible-lint and markdownlint-cli2 versions are raised along with the pinning. The ansible-lint run installs the collections of the molecule scenario, because the scenario is linted as well and depends on community.docker beside the community.general requirement of the role. Co-authored-by: Copilot <copilot@github.com>
This commit is contained in:
@@ -7,6 +7,9 @@ on:
|
|||||||
branches: [ '**' ]
|
branches: [ '**' ]
|
||||||
tags-ignore: [ '**' ]
|
tags-ignore: [ '**' ]
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
ansible-lint:
|
ansible-lint:
|
||||||
runs-on:
|
runs-on:
|
||||||
@@ -17,4 +20,6 @@ jobs:
|
|||||||
uses: ansible/ansible-lint@665d9e07a1943254d2910faffc106adaf7ea7294 # v26.8.0
|
uses: ansible/ansible-lint@665d9e07a1943254d2910faffc106adaf7ea7294 # v26.8.0
|
||||||
with:
|
with:
|
||||||
args: "--config-file .ansible-lint"
|
args: "--config-file .ansible-lint"
|
||||||
|
# The molecule scenario is linted as well, so its collections are required beside the ones of the role.
|
||||||
|
requirements_file: "molecule/default/collections.yml"
|
||||||
setup_python: "true"
|
setup_python: "true"
|
||||||
|
|||||||
@@ -7,6 +7,9 @@ on:
|
|||||||
branches: [ '**' ]
|
branches: [ '**' ]
|
||||||
tags-ignore: [ '**' ]
|
tags-ignore: [ '**' ]
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
markdown-lint:
|
markdown-lint:
|
||||||
runs-on:
|
runs-on:
|
||||||
|
|||||||
@@ -6,6 +6,9 @@ on:
|
|||||||
- '**'
|
- '**'
|
||||||
workflow_dispatch: {}
|
workflow_dispatch: {}
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
release:
|
release:
|
||||||
name: Release Ansible Role
|
name: Release Ansible Role
|
||||||
|
|||||||
Reference in New Issue
Block a user