Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update GHA allowlists #398

Open
veikkoeeva opened this issue Dec 25, 2024 · 4 comments
Open

Update GHA allowlists #398

veikkoeeva opened this issue Dec 25, 2024 · 4 comments

Comments

@veikkoeeva
Copy link
Contributor

dotnet/core#9671

@richlander
Copy link

Hi. Can you tell me what this change will do? It would be great to see the change to see if it applies to more use cases.

It sounds like you are going to change which domains a GH Action can access? Or am I reading too much into the issue title?

@richlander
Copy link

richlander commented Dec 26, 2024

Ah, is this it?

@veikkoeeva
Copy link
Contributor Author

veikkoeeva commented Dec 26, 2024

Ah, is this it?

* https://github.com/step-security/harden-runner?tab=readme-ov-file#filter-outbound-network-traffic-to-allowed-endpoints

* https://github.com/Lumoin/Verifiable/blob/a3647961b4b3f964c33093147a1c9427c1bec801/.github/workflows/main.yml#L61-L76

Yes this is it. :)

Now that I remember, probably I should also check https://github.com/Lumoin/Verifiable/blob/main/NuGet.config too.

I will late introduce more security measures for commits and releases, but likely they are not affected by this.

@richlander
Copy link

Got it. Thanks for the clarification.

We are changing Actions now so next time you update, you'll want to update your allow list.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants