Skip to content

Commit b39f564

Browse files
committed
Further GHA / harden runner tweaks
1 parent 960b59a commit b39f564

File tree

1 file changed

+8
-2
lines changed

1 file changed

+8
-2
lines changed

.github/workflows/publish.yml

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -21,10 +21,16 @@ jobs:
2121
disable-sudo: true
2222
egress-policy: block
2323
allowed-endpoints: >
24-
files.pythonhosted.org:443
2524
github.com:443
26-
pypi.org:443
2725
api.github.com:443
26+
ghcr.io:443
27+
pkg-containers.githubusercontent.com:443
28+
pypi.org:443
29+
upload.pypi.org:443
30+
files.pythonhosted.org:443
31+
fulcio.sigstore.dev:443
32+
rekor.sigstore.dev:443
33+
tuf-repo-cdn.sigstore.dev:443
2834
2935
- uses: actions/checkout@v5
3036
with:

0 commit comments

Comments
 (0)