Skip to content

[StepSecurity] Apply security best practices#442

Merged
cx-jonathan-hartman merged 1 commit into
mainfrom
chore/GHA-111218-stepsecurity-remediation
Jun 12, 2026
Merged

[StepSecurity] Apply security best practices#442
cx-jonathan-hartman merged 1 commit into
mainfrom
chore/GHA-111218-stepsecurity-remediation

Conversation

@stepsecurity-app

Copy link
Copy Markdown
Contributor

Summary

This pull request has been generated by StepSecurity as part of your enterprise subscription to ensure compliance with recommended security best practices. Please review and merge the pull request to apply these security enhancements.

Security Fixes

Runner Label Replacement

Runner labels define where GitHub Actions workflows execute. Replacing runner labels allows you to migrate workflows from one runner environment to another, such as moving from GitHub-hosted runners to self-hosted runners or vice versa.

This control automatically updates runner labels across your workflows based on the configured label mapping, ensuring consistent runner usage across your repository.

Feedback

For bug reports, feature requests, and general feedback; please create an issue in step-security/secure-repo or contact us via our website.

Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
@stepsecurity-app

Copy link
Copy Markdown
Contributor Author

Security Policy Alert: Actions Policy Violation

This workflow run has been blocked by StepSecurity's actions policy.

Disallowed Actions:

  • timonvs/pr-labeler-action@8b99f404a073744885d8021d1de4e40c6eaf38e2

To fix this issue, please modify the workflow to use only allowed actions. Contact your organization administrator to request changes to the allowed actions list if needed.

For more information, see StepSecurity's Actions Policy documentation.

@stepsecurity-app

Copy link
Copy Markdown
Contributor Author

Security Policy Alert: Actions Policy Violation

This workflow run has been blocked by StepSecurity's actions policy.

Disallowed Actions:

  • federicocarboni/setup-ffmpeg@583042d32dd1cabb8bd09df03bde06080da5c87c

To fix this issue, please modify the workflow to use only allowed actions. Contact your organization administrator to request changes to the allowed actions list if needed.

For more information, see StepSecurity's Actions Policy documentation.

@cx-jonathan-hartman cx-jonathan-hartman merged commit 128dbee into main Jun 12, 2026
3 of 9 checks passed
@cx-jonathan-hartman cx-jonathan-hartman deleted the chore/GHA-111218-stepsecurity-remediation branch June 12, 2026 16:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant