This commit is contained in:
Alexey Pustovalov 2024-02-29 13:30:55 +09:00
parent cc789f29d2
commit 1e7693d881

View File

@ -165,7 +165,7 @@ jobs:
matrix:
os: ${{ fromJson(needs.init_build.outputs.os) }}
runs-on: ubuntu-latest
runs-on: runs-on: [self-hosted, ubuntu]
permissions:
contents: read
id-token: write
@ -175,7 +175,7 @@ jobs:
uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
with:
disable-sudo: true
egress-policy: block
egress-policy: audit
allowed-endpoints: >
api.github.com:443
archive.ubuntu.com:80