File tree Expand file tree Collapse file tree 1 file changed +8
-12
lines changed Expand file tree Collapse file tree 1 file changed +8
-12
lines changed Original file line number Diff line number Diff line change 1
1
name : Code Review
2
2
on :
3
3
pull_request :
4
- branches :
5
- - main
6
- - int
7
4
permissions :
8
5
contents : read
9
-
10
6
jobs :
11
7
code-review :
12
- name : Code Review
13
8
runs-on : ubuntu-latest
14
9
permissions :
15
10
contents : read
16
- pull-requests : write
17
- id-token : write
11
+ pull-requests : read
18
12
steps :
19
13
- name : Harden Runner
20
- uses : step-security/harden-runner@6b3083af2869dc3314a0257a42f4af696cc79ba3 # v2.3.1
14
+ uses : step-security/harden-runner@128a63446a954579617e875aaab7d2978154e969 # v2.4.0
21
15
with :
22
- egress-policy : audit
16
+ disable-sudo : true
17
+ egress-policy : block
18
+ allowed-endpoints : >
19
+ api.github.com:443
20
+ int.api.stepsecurity.io:443
23
21
24
22
- name : Code Review
25
- uses : docker://ghcr.io/step-security/code-reviewer/int:latest
26
- env :
27
- PAT : ${{ secrets.GITHUB_TOKEN }}
23
+ uses : step-security/ai-codewise@int
You can’t perform that action at this time.
0 commit comments