ci(workflow): add step-security - harden runner & update actions version - v4 to v6#17
Conversation
…ions - strengthen network operations over GHA. ref: https://github.com/step-security/harden-runner
📝 WalkthroughWalkthroughThe lint workflow file was updated to include a Harden Runner security step and to upgrade GitHub Actions dependencies from version 4 to version 6 for checkout and setup-node actions. Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~8 minutes Poem
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Hi @Zafar7645, In support of your work, I would like to make a small contribution, adding step-security harden runner auditing to strengthen your GHA workflow network-bound operations, and additionally update GHA actions to their latest stable version. Hope it helps, have a good day! Best, |
|
@DAShaikh10 Fantastic addition! Thank you so much for strengthening the runner security by adding network monitoring and audit report for the same. Thank you for updating to the latest versions as well! Looking forward to more such valuable contributions. Love! Love! Love! ❤️ |
Description
Primary
Add Step-Security harden runner to audit network operations and strengthen the security of GHA workflows.
Read more: https://github.com/marketplace/actions/harden-runner
Secondary
Update the GHA actions version from
v4tov6(latest).Task
lint.ymlworkflow.v4tov6.Ref: https://github.com/DAShaikh10/syncup/actions/runs/21564293257/job/62133188660

Summary by CodeRabbit
✏️ Tip: You can customize this high-level summary in your review settings.