Skip to content

Commit d7583b0

Browse files
authored
Security changes to match dotnet=docs (#1869)
1 parent 5e14e82 commit d7583b0

File tree

3 files changed

+18
-9
lines changed

3 files changed

+18
-9
lines changed
Lines changed: 13 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,22 +1,28 @@
11
name: 'OPS status checker'
22

33
on:
4-
pull_request_target:
4+
pull_request:
55
types: [opened, synchronize, reopened]
66

7+
permissions:
8+
contents: read
9+
710
jobs:
811
status_checker_job:
912
name: Look for build warnings
1013
runs-on: ubuntu-latest
1114
permissions:
12-
statuses: write
13-
issues: write
14-
pull-requests: write
15+
statuses: read
16+
pull-requests: read
1517
steps:
16-
- uses: actions/checkout@v3
17-
- uses: dotnet/docs-tools/actions/status-checker@main
18+
- name: Harden Runner
19+
uses: step-security/harden-runner@0d381219ddf674d61a7572ddd19d7941e271515c # v2.9.0
20+
with:
21+
egress-policy: audit
22+
23+
- uses: dotnet/docs-tools/actions/status-checker@5e8bcc78465d45a7544bba56509a1a69922b6a5a # main
1824
with:
1925
repo_token: ${{ secrets.GITHUB_TOKEN }}
2026
docs_path: "dotnet-desktop-guide"
2127
url_base_path: "dotnet/desktop"
22-
opaque_leading_url_segments: "framework:view=netframeworkdesktop-4.8,net:view=netdesktop-7.0"
28+
opaque_leading_url_segments: "framework:view=netframeworkdesktop-4.8,net:view=netdesktop-7.0,net:view=netdesktop-8.0"

.github/workflows/live-protection.yml

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,7 @@
1-
on: [pull_request_target]
1+
on: [pull_request]
2+
3+
permissions:
4+
contents: read
25

36
jobs:
47
comment:

.github/workflows/rebase-needed.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@ name: "rebase required"
22

33
on:
44
push:
5-
pull_request_target:
5+
pull_request:
66
types: [synchronize]
77

88
jobs:

0 commit comments

Comments
 (0)