From 3d451ef241b13e9f3b962f57070f94917718ce0f Mon Sep 17 00:00:00 2001 From: pandeymangg Date: Wed, 1 Oct 2025 10:46:38 +0530 Subject: [PATCH 1/3] hardens the release action --- .github/workflows/publish-to-maven-central.yml | 5 ++--- .github/workflows/sonarcloud.yml | 3 ++- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/publish-to-maven-central.yml b/.github/workflows/publish-to-maven-central.yml index a155f8d..778262d 100644 --- a/.github/workflows/publish-to-maven-central.yml +++ b/.github/workflows/publish-to-maven-central.yml @@ -14,12 +14,11 @@ jobs: steps: # 1. Checkout code - name: Check out code - uses: actions/checkout@v4 + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 # 2. Set up JDK 21 - - name: Set up JDK 21 - uses: actions/setup-java@v4 + uses: actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 with: distribution: "zulu" java-version: 21 diff --git a/.github/workflows/sonarcloud.yml b/.github/workflows/sonarcloud.yml index 6aaf9ea..c9d0b3f 100644 --- a/.github/workflows/sonarcloud.yml +++ b/.github/workflows/sonarcloud.yml @@ -22,7 +22,8 @@ jobs: with: egress-policy: audit - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + - name: Check out code + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: fetch-depth: 0 # Shallow clones should be disabled for a better relevancy of analysis From 1d6c53d3e48fd6216136adbc7c90cd7756b66c2c Mon Sep 17 00:00:00 2001 From: pandeymangg Date: Wed, 1 Oct 2025 10:47:49 +0530 Subject: [PATCH 2/3] fixeS --- .github/workflows/publish-to-maven-central.yml | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-) diff --git a/.github/workflows/publish-to-maven-central.yml b/.github/workflows/publish-to-maven-central.yml index 778262d..15db725 100644 --- a/.github/workflows/publish-to-maven-central.yml +++ b/.github/workflows/publish-to-maven-central.yml @@ -12,19 +12,24 @@ jobs: name: Release build and publish runs-on: macOS-latest steps: - # 1. Checkout code + # 1. Harden Runner + - name: Harden Runner + uses: step-security/harden-runner@0634a2670c59f64b4a01f0f96f84700a4088b9f0 # v2.12.0 + with: + egress-policy: audit + + # 2. Checkout code - name: Check out code uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - # 2. Set up JDK 21 + # 3. Set up JDK 21 - name: Set up JDK 21 uses: actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 with: distribution: "zulu" java-version: 21 - # 3. Publish to Maven Central - + # 4. Publish to Maven Central - name: Publish to MavenCentral run: ./gradlew publishAndReleaseToMavenCentral --no-configuration-cache env: From fba3f561edbaf6b00bb26ed87447539a1e2d0c7c Mon Sep 17 00:00:00 2001 From: pandeymangg Date: Wed, 1 Oct 2025 10:49:07 +0530 Subject: [PATCH 3/3] bumps version --- android/build.gradle.kts | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/android/build.gradle.kts b/android/build.gradle.kts index 27cbc17..71ed102 100644 --- a/android/build.gradle.kts +++ b/android/build.gradle.kts @@ -11,7 +11,7 @@ plugins { id("org.sonarqube") version "4.4.1.3373" } -version = "1.0.2" +version = "1.1.0" val groupId = "com.formbricks" val artifactId = "android"