[release/v7.4.15] [StepSecurity] ci: Harden GitHub Actions tokens (#27231)

This commit is contained in:
Dongbo Wang
2026-04-09 10:14:26 -07:00
committed by GitHub
parent fb08d1cf9f
commit 1da44f091d
3 changed files with 70 additions and 0 deletions
+64
View File
@@ -0,0 +1,64 @@
name: "Copilot Setup Steps"
# Allow testing of the setup steps from your repository's "Actions" tab.
on:
workflow_dispatch:
pull_request:
branches:
- master
paths:
- ".github/workflows/copilot-setup-steps.yml"
permissions:
contents: read
jobs:
# The job MUST be called `copilot-setup-steps` or it will not be picked up by Copilot.
# See https://docs.github.com/en/copilot/customizing-copilot/customizing-the-development-environment-for-copilot-coding-agent
copilot-setup-steps:
runs-on: ubuntu-latest
permissions:
contents: read
# You can define any steps you want, and they will run before the agent starts.
# If you do not check out your code, Copilot will do this for you.
steps:
- uses: actions/checkout@v6
with:
fetch-depth: 1000
- name: Bootstrap
if: success()
run: |-
$title = 'Import Build.psm1'
Write-Host "::group::$title"
Import-Module ./build.psm1 -Verbose -ErrorAction Stop
Write-LogGroupEnd -Title $title
$title = 'Switch to public feed'
Write-LogGroupStart -Title $title
Switch-PSNugetConfig -Source Public
Write-LogGroupEnd -Title $title
$title = 'Bootstrap'
Write-LogGroupStart -Title $title
Start-PSBootstrap -Scenario DotNet
Write-LogGroupEnd -Title $title
$title = 'Install .NET Tools'
Write-LogGroupStart -Title $title
Start-PSBootstrap -Scenario Tools
Write-LogGroupEnd -Title $title
$title = 'Sync Tags'
Write-LogGroupStart -Title $title
Sync-PSTags -AddRemoteIfMissing
Write-LogGroupEnd -Title $title
$title = 'Setup .NET environment variables'
Write-LogGroupStart -Title $title
Find-DotNet -SetDotnetRoot
Write-LogGroupEnd -Title $title
shell: pwsh
@@ -13,6 +13,9 @@ env:
SYSTEM_ARTIFACTSDIRECTORY: ${{ github.workspace }}/artifacts
BUILD_ARTIFACTSTAGINGDIRECTORY: ${{ github.workspace }}/artifacts
permissions:
contents: read
jobs:
package:
name: ${{ matrix.architecture }} - ${{ matrix.channel }}
+3
View File
@@ -14,6 +14,9 @@ on:
required: false
default: testResults-xunit
permissions:
contents: read
jobs:
xunit:
name: Run xUnit Tests