diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 09f4568..3239b02 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -8,3 +8,15 @@ updates: bundler: patterns: - "*" + cooldown: + default-days: 7 + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "monthly" + groups: + github-actions: + patterns: + - "*" + cooldown: + default-days: 7 diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 6a1490a..e6787fe 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -17,12 +17,12 @@ jobs: CI: 1 USE_OFFICIAL_GEM_SOURCE: 1 steps: - - uses: actions/checkout@v3 - - uses: ruby/setup-ruby@v1 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + - uses: ruby/setup-ruby@14594264cd68ce8a2345dd349bc3d138a4ef85c8 # v1.327.0 with: ruby-version: ${{ matrix.ruby }} - - name: Install bundler - run: gem install bundler - name: Install dependencies run: bundle install - run: bundle exec rspec diff --git a/.github/workflows/push_gem.yml b/.github/workflows/push_gem.yml index 63b0cc2..befbebe 100644 --- a/.github/workflows/push_gem.yml +++ b/.github/workflows/push_gem.yml @@ -22,16 +22,20 @@ jobs: steps: # Set up - name: Harden Runner - uses: step-security/harden-runner@4d991eb9b905ef189e4c376166672c3f2f230481 # v2.11.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: audit - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + with: + persist-credentials: false - name: Set up Ruby uses: ruby/setup-ruby@2e007403fc1ec238429ecaa57af6f22f019cc135 # v1.234.0 with: - bundler-cache: true ruby-version: ruby + # Not bundler-cache: a release shouldn't restore a cache other workflows can write. + - name: Install gems + run: bundle install # Release - - uses: rubygems/release-gem@9e85cb11501bebc2ae661c1500176316d3987059 # v1 + - uses: rubygems/release-gem@9e85cb11501bebc2ae661c1500176316d3987059 # v1.1.0 diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml new file mode 100644 index 0000000..e5a0721 --- /dev/null +++ b/.github/workflows/zizmor.yml @@ -0,0 +1,16 @@ +name: GitHub Actions Security Analysis + +on: + push: + branches: [main] + pull_request: + branches: ["**"] + +permissions: {} + +jobs: + zizmor: + permissions: + contents: read + security-events: write + uses: rubyatscale/shared-config/.github/workflows/zizmor.yml@main # zizmor: ignore[unpinned-uses] internal reusable workflow tracked at @main by convention so shared-config updates propagate automatically