瀏覽代碼

Update clangd-tidy endpoint whitelist (#6855)

Missed in #6848 (had it sitting in my workspace uncommitted, apparently
have gotten too used to jj; using git here)

Assisted-by: Google Antigravity with Gemini
Jon Ross-Perkins 1 月之前
父節點
當前提交
0dac40e793
共有 2 個文件被更改,包括 11 次插入2 次删除
  1. 1 0
      .github/workflows/README.md
  2. 10 2
      .github/workflows/clangd_tidy.yaml

+ 1 - 0
.github/workflows/README.md

@@ -18,6 +18,7 @@ the "Harden Runner" steps are
 Most jobs only have a few endpoints, but due to tools which do downloads, a few
 have significantly more. These are:
 
+-   clangd_tidy.yaml (Bazel)
 -   pre_commit.yaml (Bazel, pre-commit)
 -   nightly_release.yaml (Bazel)
 -   tests.yaml (Bazel)

+ 10 - 2
.github/workflows/clangd_tidy.yaml

@@ -32,19 +32,27 @@ jobs:
           # When adding endpoints, see README.md.
           # prettier-ignore
           allowed-endpoints: >
-            *.dl.sourceforge.net:443
+            *.blob.storage.azure.net:443
+            *.githubapp.com:443
+            *.sourceforge.net:443
             api.github.com:443
+            api.ipify.org:443
             bcr.bazel.build:443
             downloads.sourceforge.net:443
+            files.pythonhosted.org:443
             github.com:443
+            go.dev:443
+            mirror.bazel.build:443
             mirrors.kernel.org:443
             nodejs.org:443
             oauth2.googleapis.com:443
             objects.githubusercontent.com:443
             pypi.org:443
+            registry.npmjs.org:443
+            release-assets.githubusercontent.com:443
             releases.bazel.build:443
-            sourceforge.net:443
             storage.googleapis.com:443
+            www.googleapis.com:443
 
       - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2