Skip to content

Merge pull request #326 from redhat-cop/renovate/step-security-harden… #734

Merge pull request #326 from redhat-cop/renovate/step-security-harden…

Merge pull request #326 from redhat-cop/renovate/step-security-harden… #734

Workflow file for this run

name: Run opa-profile.sh
on: [push, pull_request]
# Declare default permissions as read only.
permissions: read-all
jobs:
opa:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1
with:
egress-policy: audit
- name: Checkout
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
- name: Opa eval --profile
uses: redhat-cop/github-actions/confbatstest@1a584131f8a335296e866d1fb0988870ca83aefb # v4.3
with:
tests: _test/opa-profile.sh
policies: '[]' # An empty array is provided as the policies are already cloned via source.
- name: Upload opa-profile.log
uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # v4
with:
name: profile-results
path: opa-profile.log