fix(ci): pin actions to their commit sha
Floating tags let a compromised or force pushed release change what the workflows execute. Pinning the actions to a commit sha and restricting the default token to read access limits the blast radius of a supply chain attack. The outdated ansible-lint and markdownlint-cli2 versions are raised along with the pinning. The ansible-lint run installs the collections of the molecule scenario, because the scenario is linted as well and depends on community.docker beside the community.general requirement of the role. Co-authored-by: Copilot <copilot@github.com>
This commit is contained in:
@@ -7,6 +7,9 @@ on:
|
||||
branches: [ '**' ]
|
||||
tags-ignore: [ '**' ]
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
ansible-lint:
|
||||
runs-on:
|
||||
@@ -17,4 +20,6 @@ jobs:
|
||||
uses: ansible/ansible-lint@665d9e07a1943254d2910faffc106adaf7ea7294 # v26.8.0
|
||||
with:
|
||||
args: "--config-file .ansible-lint"
|
||||
# The molecule scenario is linted as well, so its collections are required beside the ones of the role.
|
||||
requirements_file: "molecule/default/collections.yml"
|
||||
setup_python: "true"
|
||||
|
||||
@@ -7,6 +7,9 @@ on:
|
||||
branches: [ '**' ]
|
||||
tags-ignore: [ '**' ]
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
markdown-lint:
|
||||
runs-on:
|
||||
|
||||
@@ -6,6 +6,9 @@ on:
|
||||
- '**'
|
||||
workflow_dispatch: {}
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
release:
|
||||
name: Release Ansible Role
|
||||
|
||||
Reference in New Issue
Block a user