diff --git a/.github/workflows/reusable-fossa.yml b/.github/workflows/reusable-fossa.yml index 236f18e..98496e7 100644 --- a/.github/workflows/reusable-fossa.yml +++ b/.github/workflows/reusable-fossa.yml @@ -19,7 +19,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Harden Runner - uses: step-security/harden-runner@1f99358870fe1c846a3ccba386cc2b2246836776 # v2.2.1 + uses: step-security/harden-runner@1b05615854632b887b69ae1be8cbefe72d3ae423 # v2.6.0 with: disable-sudo: true egress-policy: block @@ -29,6 +29,7 @@ jobs: api.github.com:443 raw.githubusercontent.com:443 objects.githubusercontent.com:443 + storage.googleapis.com:443 proxy.golang.org:443 sum.golang.org:443 app.fossa.com:443