Floating tags let a compromised or force pushed release change what the workflows execute. Pinning the actions to a commit sha and restricting the default token to read access limits the blast radius of a supply chain attack. The outdated ansible-lint and markdownlint-cli2 versions are raised along with the pinning. The ansible-lint run installs the collections of the molecule scenario, because the scenario is linted as well and depends on community.docker beside the community.general requirement of the role. Co-authored-by: Copilot <copilot@github.com>
25 lines
555 B
YAML
25 lines
555 B
YAML
name: Release Ansible Role
|
|
|
|
on:
|
|
push:
|
|
tags:
|
|
- '**'
|
|
workflow_dispatch: {}
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
release:
|
|
name: Release Ansible Role
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Install Ansible Galaxy
|
|
run: |
|
|
apt update --yes
|
|
apt install --yes ansible
|
|
- env:
|
|
ANSIBLE_GALAXY_TOKEN: ${{ secrets.ANSIBLE_GALAXY_TOKEN }}
|
|
name: Update Ansible Role in Ansible Galaxy
|
|
run: |
|
|
ansible-galaxy role import --token=${ANSIBLE_GALAXY_TOKEN} volker-raschek ${GITHUB_REPOSITORY#*/} |