From 0e2641d9f9e6e7d947f8ec7f05327ec432370a27 Mon Sep 17 00:00:00 2001 From: StepSecurity Bot Date: Wed, 11 Sep 2024 11:50:00 -0700 Subject: [PATCH] [StepSecurity] Apply security best practices (#172) --- .github/dependabot.yml | 9 +++++++-- .github/workflows/codeql.yml | 8 ++++---- .github/workflows/main.yml | 4 ++-- .github/workflows/msbuild.yml | 4 ++-- .github/workflows/msvc.yml | 6 +++--- .github/workflows/test.yml | 8 ++++---- .github/workflows/vcpkg.yml | 6 +++--- .github/workflows/wsl.yml | 6 +++--- 8 files changed, 28 insertions(+), 23 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 9786d53..0e5fcb9 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -1,8 +1,13 @@ version: 2 updates: - - package-ecosystem: "nuget" + - package-ecosystem: nuget directory: "/UVAtlasTool" schedule: - interval: "weekly" + interval: weekly commit-message: prefix: "[nuget] " + + - package-ecosystem: github-actions + directory: / + schedule: + interval: daily diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 6b1cf85..99a633e 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -37,15 +37,15 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v4 + uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7 - name: 'Install Ninja' run: choco install ninja - - uses: ilammy/msvc-dev-cmd@v1 + - uses: ilammy/msvc-dev-cmd@0b201ec74fa43914dc39ae48a89fd1d8cb592756 # v1.13.0 - name: Initialize CodeQL - uses: github/codeql-action/init@v3 + uses: github/codeql-action/init@4dd16135b69a43b6c8efb853346f8437d92d3c93 # v3.26.6 with: languages: c-cpp build-mode: manual @@ -59,6 +59,6 @@ jobs: run: cmake --build out\build\x64-Debug - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@v3 + uses: github/codeql-action/analyze@4dd16135b69a43b6c8efb853346f8437d92d3c93 # v3.26.6 with: category: "/language:c-cpp" diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml index 55b4c8d..4090522 100644 --- a/.github/workflows/main.yml +++ b/.github/workflows/main.yml @@ -72,12 +72,12 @@ jobs: arch: amd64_arm64 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7 - name: 'Install Ninja' run: choco install ninja - - uses: ilammy/msvc-dev-cmd@v1 + - uses: ilammy/msvc-dev-cmd@0b201ec74fa43914dc39ae48a89fd1d8cb592756 # v1.13.0 with: arch: ${{ matrix.arch }} diff --git a/.github/workflows/msbuild.yml b/.github/workflows/msbuild.yml index 9a1a3e3..0be71ab 100644 --- a/.github/workflows/msbuild.yml +++ b/.github/workflows/msbuild.yml @@ -32,10 +32,10 @@ jobs: platform: [x86, x64, ARM64] steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7 - name: Add MSBuild to PATH - uses: microsoft/setup-msbuild@v2 + uses: microsoft/setup-msbuild@6fb02220983dee41ce7ae257b6f4d8f9bf5ed4ce # v2.0.0 - if: matrix.platform != 'ARM64' name: Restore NuGet packages diff --git a/.github/workflows/msvc.yml b/.github/workflows/msvc.yml index afb440f..4732265 100644 --- a/.github/workflows/msvc.yml +++ b/.github/workflows/msvc.yml @@ -35,14 +35,14 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v4 + uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7 - name: Configure CMake working-directory: ${{ github.workspace }} run: cmake -B out -DCMAKE_DISABLE_PRECOMPILE_HEADERS=ON - name: Initialize MSVC Code Analysis - uses: microsoft/msvc-code-analysis-action@v0.1.1 + uses: microsoft/msvc-code-analysis-action@24c285ab36952c9e9182f4b78dfafbac38a7e5ee # v0.1.1 id: run-analysis with: cmakeBuildDirectory: ./out @@ -51,6 +51,6 @@ jobs: # Upload SARIF file to GitHub Code Scanning Alerts - name: Upload SARIF to GitHub - uses: github/codeql-action/upload-sarif@v3 + uses: github/codeql-action/upload-sarif@4dd16135b69a43b6c8efb853346f8437d92d3c93 # v3.26.6 with: sarif_file: ${{ steps.run-analysis.outputs.sarif }} diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 1eb8fca..4f9fee2 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -85,10 +85,10 @@ jobs: arch: amd64 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7 - name: Clone test repository - uses: actions/checkout@v4 + uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7 with: repository: walbourn/uvatlastest path: Tests @@ -97,7 +97,7 @@ jobs: - name: 'Install Ninja' run: choco install ninja - - uses: ilammy/msvc-dev-cmd@v1 + - uses: ilammy/msvc-dev-cmd@0b201ec74fa43914dc39ae48a89fd1d8cb592756 # v1.13.0 with: arch: ${{ matrix.arch }} @@ -128,7 +128,7 @@ jobs: echo "::error Unknown architecture/build-type triplet mapping" } - - uses: lukka/run-vcpkg@v11 + - uses: lukka/run-vcpkg@7d259227a1fb6471a0253dd5ab7419835228f7d7 # v11 with: runVcpkgInstall: true vcpkgJsonGlob: '**/build/vcpkg.json' diff --git a/.github/workflows/vcpkg.yml b/.github/workflows/vcpkg.yml index ee171ec..4b5aa26 100644 --- a/.github/workflows/vcpkg.yml +++ b/.github/workflows/vcpkg.yml @@ -43,12 +43,12 @@ jobs: arch: amd64 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7 - name: 'Install Ninja' run: choco install ninja - - uses: ilammy/msvc-dev-cmd@v1 + - uses: ilammy/msvc-dev-cmd@0b201ec74fa43914dc39ae48a89fd1d8cb592756 # v1.13.0 with: arch: ${{ matrix.arch }} @@ -79,7 +79,7 @@ jobs: echo "::error Unknown architecture/build-type triplet mapping" } - - uses: lukka/run-vcpkg@v11 + - uses: lukka/run-vcpkg@7d259227a1fb6471a0253dd5ab7419835228f7d7 # v11 with: runVcpkgInstall: true vcpkgJsonGlob: '**/build/vcpkg.json' diff --git a/.github/workflows/wsl.yml b/.github/workflows/wsl.yml index c632e9c..a46935a 100644 --- a/.github/workflows/wsl.yml +++ b/.github/workflows/wsl.yml @@ -31,11 +31,11 @@ jobs: gcc: [10, 11, 12] steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7 - - uses: seanmiddleditch/gha-setup-ninja@v5 + - uses: seanmiddleditch/gha-setup-ninja@96bed6edff20d1dd61ecff9b75cc519d516e6401 # v5 - - uses: lukka/run-vcpkg@v11 + - uses: lukka/run-vcpkg@7d259227a1fb6471a0253dd5ab7419835228f7d7 # v11 with: runVcpkgInstall: true vcpkgJsonGlob: '**/build/vcpkg.json'