Skip to content

use sigstore only when publishing via github actions #5041

use sigstore only when publishing via github actions

use sigstore only when publishing via github actions #5041

name: Validate Gradle Wrapper
on: [push, pull_request]
permissions: read-all
jobs:
validation:
name: Validation
runs-on: ubuntu-latest
steps:
- name: Harden Runner
uses: step-security/harden-runner@0080882f6c36860b6ba35c610c98ce87d4e2f26f # v2.10.2
with:
disable-sudo: true
egress-policy: block
allowed-endpoints: >
downloads.gradle.org:443
downloads.gradle-dn.com:443
github.com:443
services.gradle.org:443
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: gradle/actions/wrapper-validation@0bdd871935719febd78681f197cd39af5b6e16a6 # v4.2.2