Skip to content

Commit 1417961

Browse files
authored
Merge branch 'main' into scorecards-cleanup
2 parents ca7851b + 439f90a commit 1417961

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

68 files changed

+1753
-346
lines changed

.github/workflows/codeql-analysis.yml

+4-4
Original file line numberDiff line numberDiff line change
@@ -52,7 +52,7 @@ jobs:
5252

5353
steps:
5454
- name: Harden Runner
55-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
55+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
5656
with:
5757
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
5858

@@ -61,7 +61,7 @@ jobs:
6161

6262
# Initializes the CodeQL tools for scanning.
6363
- name: Initialize CodeQL
64-
uses: github/codeql-action/init@18fe527fa8b29f134bb91f32f1a5dc5abb15ed7f # v1
64+
uses: github/codeql-action/init@c3b6fce4ee2ca25bc1066aa3bf73962fda0e8898 # v1
6565
with:
6666
languages: ${{ matrix.language }}
6767
queries: +security-extended
@@ -73,7 +73,7 @@ jobs:
7373
# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
7474
# If this step fails, then you should remove it and run the build manually (see below)
7575
- name: Autobuild
76-
uses: github/codeql-action/autobuild@18fe527fa8b29f134bb91f32f1a5dc5abb15ed7f # v1
76+
uses: github/codeql-action/autobuild@c3b6fce4ee2ca25bc1066aa3bf73962fda0e8898 # v1
7777

7878
# ℹ️ Command-line programs to run using the OS shell.
7979
# 📚 https://git.io/JvXDl
@@ -87,4 +87,4 @@ jobs:
8787
# make release
8888

8989
- name: Perform CodeQL Analysis
90-
uses: github/codeql-action/analyze@18fe527fa8b29f134bb91f32f1a5dc5abb15ed7f # v1
90+
uses: github/codeql-action/analyze@c3b6fce4ee2ca25bc1066aa3bf73962fda0e8898 # v1

.github/workflows/depsreview.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -24,4 +24,4 @@ jobs:
2424
- name: 'Checkout Repository'
2525
uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8
2626
- name: 'Dependency Review'
27-
uses: actions/dependency-review-action@0efb1d1d84fc9633afcdaad14c485cbbc90ef46c
27+
uses: actions/dependency-review-action@30d582111533d59ab793fd9f971817241654f3ec

.github/workflows/docker.yml

+7-7
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,7 @@ jobs:
4141
contents: read
4242
steps:
4343
- name: Harden Runner
44-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
44+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
4545
with:
4646
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
4747

@@ -86,7 +86,7 @@ jobs:
8686
contents: read
8787
steps:
8888
- name: Harden Runner
89-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
89+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
9090
with:
9191
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
9292

@@ -131,7 +131,7 @@ jobs:
131131
contents: read
132132
steps:
133133
- name: Harden Runner
134-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
134+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
135135
with:
136136
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
137137

@@ -176,7 +176,7 @@ jobs:
176176
contents: read
177177
steps:
178178
- name: Harden Runner
179-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
179+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
180180
with:
181181
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
182182

@@ -221,7 +221,7 @@ jobs:
221221
contents: read
222222
steps:
223223
- name: Harden Runner
224-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
224+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
225225
with:
226226
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
227227

@@ -266,7 +266,7 @@ jobs:
266266
contents: read
267267
steps:
268268
- name: Harden Runner
269-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
269+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
270270
with:
271271
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
272272

@@ -311,7 +311,7 @@ jobs:
311311
contents: read
312312
steps:
313313
- name: Harden Runner
314-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
314+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
315315
with:
316316
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
317317

.github/workflows/goreleaser.yaml

+1-1
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ jobs:
3131
runs-on: ubuntu-latest
3232
steps:
3333
- name: Harden Runner
34-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
34+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
3535
with:
3636
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
3737

.github/workflows/integration.yml

+3-4
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ jobs:
2525
runs-on: ubuntu-latest
2626
steps:
2727
- name: Harden Runner
28-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
28+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
2929
with:
3030
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
3131

@@ -38,7 +38,7 @@ jobs:
3838
needs: [approve]
3939
steps:
4040
- name: Harden Runner
41-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
41+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
4242
with:
4343
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
4444

@@ -76,7 +76,7 @@ jobs:
7676
retry_on: error
7777
timeout_minutes: 30
7878
command: make e2e-pat
79-
79+
8080
- name: Run attestor e2e #using retry because the GitHub token is being throttled.
8181
uses: nick-invision/retry@3e91a01664abd3c5cd539100d10d33b9c5b68482
8282
env:
@@ -90,7 +90,6 @@ jobs:
9090
- name: codecov
9191
uses: codecov/codecov-action@81cd2dc8148241f03f5839d295e000b8f761e378 # 2.1.0
9292
with:
93-
fail_ci_if_error: true
9493
files: ./e2e-coverage.out,./attestor/e2e/e2e-coverage.out
9594
verbose: true
9695

.github/workflows/main.yml

+20-21
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@ jobs:
3737
contents: read
3838
steps:
3939
- name: Harden Runner
40-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
40+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
4141
with:
4242
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
4343

@@ -68,7 +68,6 @@ jobs:
6868
- name: Upload codecoverage
6969
uses: codecov/codecov-action@81cd2dc8148241f03f5839d295e000b8f761e378 # 2.1.0
7070
with:
71-
fail_ci_if_error: true
7271
files: ./unit-coverage.out,./attestor/unit-coverage.out
7372
verbose: true
7473
generate-mocks:
@@ -78,7 +77,7 @@ jobs:
7877
contents: read
7978
steps:
8079
- name: Harden Runner
81-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
80+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
8281
with:
8382
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
8483

@@ -126,7 +125,7 @@ jobs:
126125
contents: read
127126
steps:
128127
- name: Harden Runner
129-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
128+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
130129
with:
131130
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
132131

@@ -173,7 +172,7 @@ jobs:
173172
contents: read
174173
steps:
175174
- name: Harden Runner
176-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
175+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
177176
with:
178177
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
179178

@@ -209,7 +208,7 @@ jobs:
209208
contents: read
210209
steps:
211210
- name: Harden Runner
212-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
211+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
213212
with:
214213
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
215214

@@ -257,7 +256,7 @@ jobs:
257256
contents: read
258257
steps:
259258
- name: Harden Runner
260-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
259+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
261260
with:
262261
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
263262

@@ -305,7 +304,7 @@ jobs:
305304
contents: read
306305
steps:
307306
- name: Harden Runner
308-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
307+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
309308
with:
310309
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
311310

@@ -353,7 +352,7 @@ jobs:
353352
contents: read
354353
steps:
355354
- name: Harden Runner
356-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
355+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
357356
with:
358357
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
359358

@@ -401,7 +400,7 @@ jobs:
401400
contents: read
402401
steps:
403402
- name: Harden Runner
404-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
403+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
405404
with:
406405
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
407406

@@ -449,7 +448,7 @@ jobs:
449448
contents: read
450449
steps:
451450
- name: Harden Runner
452-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
451+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
453452
with:
454453
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
455454

@@ -497,7 +496,7 @@ jobs:
497496
contents: read
498497
steps:
499498
- name: Harden Runner
500-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
499+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
501500
with:
502501
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
503502

@@ -545,7 +544,7 @@ jobs:
545544
contents: read
546545
steps:
547546
- name: Harden Runner
548-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
547+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
549548
with:
550549
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
551550

@@ -593,7 +592,7 @@ jobs:
593592
contents: read
594593
steps:
595594
- name: Harden Runner
596-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
595+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
597596
with:
598597
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
599598

@@ -641,7 +640,7 @@ jobs:
641640
contents: read
642641
steps:
643642
- name: Harden Runner
644-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
643+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
645644
with:
646645
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
647646

@@ -689,7 +688,7 @@ jobs:
689688
contents: read
690689
steps:
691690
- name: Harden Runner
692-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
691+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
693692
with:
694693
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
695694

@@ -736,7 +735,7 @@ jobs:
736735
contents: read
737736
steps:
738737
- name: Harden Runner
739-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
738+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
740739
with:
741740
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
742741

@@ -766,7 +765,7 @@ jobs:
766765
contents: read
767766
steps:
768767
- name: Harden Runner
769-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
768+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
770769
with:
771770
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
772771

@@ -809,7 +808,7 @@ jobs:
809808
contents: read
810809
steps:
811810
- name: Harden Runner
812-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
811+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
813812
with:
814813
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
815814
- name: Install Protoc
@@ -855,7 +854,7 @@ jobs:
855854
contents: read
856855
steps:
857856
- name: Harden Runner
858-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
857+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
859858
with:
860859
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
861860

@@ -890,7 +889,7 @@ jobs:
890889
contents: read
891890
steps:
892891
- name: Harden Runner
893-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
892+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
894893
with:
895894
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
896895

.github/workflows/publishimage.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@ jobs:
3535
COSIGN_EXPERIMENTAL: "true"
3636
steps:
3737
- name: Harden Runner
38-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34
38+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5
3939
with:
4040
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
4141

.github/workflows/scorecard-analysis.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -48,6 +48,6 @@ jobs:
4848
retention-days: 5
4949

5050
- name: "Upload SARIF results"
51-
uses: github/codeql-action/upload-sarif@18fe527fa8b29f134bb91f32f1a5dc5abb15ed7f # v1
51+
uses: github/codeql-action/upload-sarif@c3b6fce4ee2ca25bc1066aa3bf73962fda0e8898 # v1
5252
with:
5353
sarif_file: results.sarif

.github/workflows/stale.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ jobs:
2727
runs-on: ubuntu-latest
2828
steps:
2929
- name: Harden Runner
30-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
30+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
3131
with:
3232
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
3333

.github/workflows/verify.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ jobs:
2626
runs-on: ubuntu-latest
2727
steps:
2828
- name: Harden Runner
29-
uses: step-security/harden-runner@2e205a28d0e1da00c5f53b161f4067b052c61f34 # v1
29+
uses: step-security/harden-runner@ebacdc22ef6c2cfb85ee5ded8f2e640f4c776dd5 # v1
3030
with:
3131
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
3232

attestor/go.mod

+3-3
Original file line numberDiff line numberDiff line change
@@ -55,7 +55,7 @@ require (
5555
github.com/spf13/pflag v1.0.5 // indirect
5656
github.com/vbatts/tar-split v0.11.2 // indirect
5757
golang.org/x/sync v0.1.0 // indirect
58-
golang.org/x/term v0.1.0 // indirect
58+
golang.org/x/term v0.2.0 // indirect
5959
golang.org/x/time v0.0.0-20220922220347-f3bd1da661af // indirect
6060
gopkg.in/inf.v0 v0.9.1 // indirect
6161
gopkg.in/yaml.v3 v3.0.1 // indirect
@@ -100,9 +100,9 @@ require (
100100
go.opencensus.io v0.23.0 // indirect
101101
gocloud.dev v0.26.0 // indirect
102102
golang.org/x/crypto v0.1.0 // indirect
103-
golang.org/x/net v0.1.0 // indirect
103+
golang.org/x/net v0.2.0 // indirect
104104
golang.org/x/oauth2 v0.1.0 // indirect
105-
golang.org/x/sys v0.1.0 // indirect
105+
golang.org/x/sys v0.2.0 // indirect
106106
golang.org/x/text v0.4.0 // indirect
107107
golang.org/x/xerrors v0.0.0-20220907171357-04be3eba64a2 // indirect
108108
google.golang.org/api v0.99.0 // indirect

0 commit comments

Comments
 (0)